Druva insync windows client 6.6.3 local privilege escalation (powershell) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-12-07 |
Type : local |
Platform : windows
This exploit / vulnerability Druva insync windows client 6.6.3 local privilege escalation (powershell) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
# Date: 2020-12-03
# Exploit Author: 1F98D
# Original Author: Matteo Malvica
# Vendor Homepage: druva.com
# Software Link: https://downloads.druva.com/downloads/inSync/Windows/6.6.3/inSync6.6.3r102156.msi
# Version: 6.6.3
# Tested on: Windows 10 (x64)
# CVE: CVE-2020-5752
# References: https://www.matteomalvica.com/blog/2020/05/21/lpe-path-traversal/
# Druva inSync exposes an RPC service which is vulnerable to a command injection attack.