ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.
The ZKTimeNet3.0 installation directory and its contents have write permissions for all system users (world-writable). An unprivileged user can replace legitimate executable files with malicious binaries. When the replaced file is executed in a higher privilege context (e.g., by a service or administrator), the attacker gains privilege escalation.
An attacker can obtain elevated privileges on the system, potentially gaining full control over the host. The consequence may be arbitrary code execution in a privileged context (privilege escalation/LPE).
Patches available from the vendor must be applied in accordance with the references. As a workaround, immediately restrict permissions to the ZKTimeNet3.0 directory and its contents, preventing unprivileged users from writing to application executable files.
ZKTeco ZKTime.Net version 3.0.1.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X