CVE-2017-20218
7.8Serviio · Serviio PRO
Serviio PRO contains an unquoted search path vulnerability and improper directory permissions, allowing local users to achieve privilege escalation by executing arbitrary code.
Executive summary
A local privilege escalation vulnerability in Serviio PRO allows authenticated users to execute arbitrary code with elevated system privileges.
Vulnerability
The application is susceptible to an unquoted search path vulnerability and improper directory permissions, which allow an authenticated local user to replace the service executable or hijack the search path to execute arbitrary code with elevated LocalSystem privileges.
Business impact
Successful exploitation of this vulnerability permits a local user to gain full administrative control over the host system. Given the CVSS score of 7.8, this represents a significant risk, as it facilitates complete system compromise, unauthorized data access, and potential lateral movement within the network.
Remediation
Immediate Action: Since a specific patch is not confirmed, restrict local access to the Serviio installation directory and ensure that non-privileged users do not have modify permissions on the service executable.
Proactive Monitoring: Monitor Windows system logs for unexpected service restarts or modifications to the Serviio service configuration.
Compensating Controls: Use Group Policy to enforce strict NTFS permissions on the Serviio application folder to prevent unauthorized users from modifying or replacing system binaries.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the Exploit-DB entry 41959 and Packet Storm Security.
Analyst recommendation
This vulnerability presents a high risk to environment integrity due to the potential for full system compromise. Administrators should immediately audit the permissions of the Serviio installation directory and restrict write access to authorized accounts only, while awaiting further guidance or official patches from the vendor.
More Serviio CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure Third-party advisory
- SecuriTeam Blogs Third-party advisory
- Exploit-DB Exploit / PoC
- Packet Storm Security Exploit / PoC
- CXSecurity Third-party advisory
- IBM X-Force Exchange Vulnerability database entry
- VulnCheck Advisory: Serviio PRO 1.8 Local Privilege Escalation via Unquoted Path Third-party advisory