ZDI-20-1217: Micro Focus Operations Bridge Reporter HPE-OBR Incorrect Permission Assignment Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Micro Focus Operations Bridge Reporter. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product's installer. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-1217?
The severity of ZDI-20-1217 is considered critical as it allows privilege escalation.
How do I fix ZDI-20-1217?
To fix ZDI-20-1217, it is recommended to apply the latest security updates provided by Micro Focus for Operations Bridge Reporter.
What type of vulnerabilities does ZDI-20-1217 exploit?
ZDI-20-1217 exploits privilege escalation vulnerabilities that require local access to a system.
Which software is affected by ZDI-20-1217?
ZDI-20-1217 affects Micro Focus Operations Bridge Reporter installations.
What prerequisite does an attacker need to exploit ZDI-20-1217?
An attacker must first be able to execute low-privileged code on the target system to exploit ZDI-20-1217.