CVE-2016-6914
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
- Affected products
- Unifi Video
- Ui Unifi Video
- < 3.8.0
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.2% (64th percentile)
- Weakness
- CWE-276
- NVD status
- Modified
- Published
- 2017-12-27
CVE-2016-6914 at NVD
5 known exploits for CVE-2016-6914
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Cross-site Scripting in Astaro Security_Gateway_Software
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
Ubiquiti UniFi Video 3.7.3 Local Privilege Escalation Vulnerability
Ubiquiti UniFi Video 3.7.3 (Windows) Local Privilege Escalation