CVE-2016-20025

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/03/2026
Last modified:
15/04/2026

Description

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for privilege escalation.