CVE-2016-6914: High severity ubiquiti unifi video controller vulnerability
Published Dec 27, 2017
·Updated
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
Affected Software
2 affected components
UI UniFi Video<3.8.0
Microsoft Windows
Event History
Dec 27, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Ubiquiti UniFi Video?
The vulnerability ID for Ubiquiti UniFi Video is CVE-2016-6914.
2
What is the title of the vulnerability for Ubiquiti UniFi Video?
The title of the vulnerability for Ubiquiti UniFi Video is 'Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory.'
3
What is the severity of CVE-2016-6914?
The severity of CVE-2016-6914 is high with a severity value of 7.8.
4
How does the vulnerability in Ubiquiti UniFi Video affect local users?
The vulnerability in Ubiquiti UniFi Video allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
5
How can I fix the vulnerability in Ubiquiti UniFi Video?
To fix the vulnerability in Ubiquiti UniFi Video, update to version 3.8.0 or later.