CloudBerry Backup v6.1.2.34 Local Privilege Escalation
- by Vince
-
in Blog
-
Hits: 7588
Disclosure date: 08/26/19
CVE-2019-15720
CloudBerry Backup v6.1.2.34 and possibly older versions are vulnerable to local privilege escalation via the Pre and Post backup action. With only user level access, the user can modify the backup plan and add a Pre backup action script which executes on behalf of NT AUTHORITY\SYSTEM.
Cloudberry Lab was notified of this vulnerability on 8/23/19 and acknowledged the issue in the subsequent days.