LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2016-20025

Published
CVSS8.8
Severityhigh
WeaknessCWE-552
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for privilege escalation.

References

← Back to the CVE Tracker

Our coverage of CVE-2016-20025

No stories yet. This page updates automatically when we publish reporting that references CVE-2016-20025.