CVE-2017-6554
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
14/04/2017
Last modified:
20/04/2025
Description
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:quest:privilege_manager:6.0.0-27:*:*:*:*:*:*:* | ||
cpe:2.3:a:quest:privilege_manager:6.0.0-50:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/142095/Quest-Privilege-Manager-6.0.0-Arbitrary-File-Write.html
- http://www.securityfocus.com/bid/97686
- https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/
- https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824
- https://www.exploit-db.com/exploits/41861/
- http://packetstormsecurity.com/files/142095/Quest-Privilege-Manager-6.0.0-Arbitrary-File-Write.html
- http://www.securityfocus.com/bid/97686
- https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/
- https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824
- https://www.exploit-db.com/exploits/41861/