Privilege Escalation via File Replacement in Diasoft File Replication Pro 7.5.0

Privilege Escalation via File Replacement in Diasoft File Replication Pro 7.5.0

CVE-2023-26918 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

Learn more about our Web Application Penetration Testing UK.