|
|
|
![]() |
Vulnerability Note VU#124289Nik Software Sharpener Pro vulnerable to privilege escalationOverviewThe Nik Software Shapener Pro installs files with insecure permissions, which may allow a local attacker to elevate privileges.I. DescriptionNik Software Sharpener Pro is an Adobe Photoshop plug-in that provides image sharpening capabilities. The Nik Software Sharpener Pro installer sets insecure permissions on the plug-in files. The plug-ins can contain executable code, yet they are world-writable.II. ImpactAn unprivileged user may be able to modify files that can be executed by other users, which can allow privilege escalation.III. SolutionWe are currently unaware of a practical solution to this problem. Please consider the following workaround:Remove write access to the Nik Sharpener plug-in files
References
Thanks to Vlad Didenko for reporting this vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||