In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HIxpdata Easyinstall
APPIxpdata6.2.13723
Related vulnerabilities
RCE i privilege escalation w IXP EasyInstall przez nieuwierzytelnione API
RCE w IXP EasyInstall — nieuwierzytelnione wykonanie kodu jako SYSTEM
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of pe...
An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecur...
An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges...