Thursday, June 30, 2022

CVE-2022-34006

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674 (sub-issue 2). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation. (CVSS:7.2) (Last Update:2022-06-29)
http://dlvr.it/ST7NxK

No comments:

Post a Comment

CISA says SonicWall bug being exploited as experts warn of ransomware gang use - The Record from Recorded Future News

CISA says SonicWall bug being exploited as experts warn of ransomware gang use  The Record from Recorded Future News http://dlvr.it/TD4N1S