GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.
The GFI Archiver installer contains a vulnerable version of the Telerik Web UI component. An attacker can exploit known weaknesses of this component to execute code without the need for any credentials. The code is executed in the context of the NETWORK SERVICE account.
An attacker can remotely execute arbitrary code on the compromised system, resulting in complete breach of confidentiality, integrity, and availability of data. In practice, it is possible to take control of the server hosting GFI Archiver.
Apply patches available from the vendor in accordance with references. It is also recommended to restrict network access to the GFI Archiver web interface exclusively to trusted hosts until the patch is deployed.
GFI Archiver installations – specific versions indicated in vendor references and in the Zero Day Initiative guide (ZDI-24-1671)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGfi Archiver
APPGfi< 15.7
Related vulnerabilities
GFI Archiver: Pominięcie autoryzacji w MArc.Store umożliwia RCE jako SYSTEM
GFI Archiver MArc.Core — pominięcie autoryzacji (Authentication Bypass)
GFI Mail Archiver — nieograniczony upload pliku przez podatny plugin Telerik Web UI
GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabil...
GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabili...