An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.
Software | From | Fixed in |
---|---|---|
advantech / webaccess/scada | 9.0.1 | 9.0.1.x |