An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).
References
Link | Resource |
---|---|
https://medium.com/@tomerp_77017/exploiting-listary-searching-your-way-to-system-privileges-8175af676c3e | Exploit Third Party Advisory |
https://www.listary.com/download | Vendor Advisory |
Configurations
Information
Published : 2021-12-14 08:15
Updated : 2021-12-20 09:04
NVD link : CVE-2021-41066
Mitre link : CVE-2021-41066
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
bopsoft
- listary