Finding a Privilege Escalation in the Intel Trusted…
ID: 554bf8f7-d06b-5be5-ab8e-bb8c0271da88
STIX ID: report--554bf8f7-d06b-5be5-ab8e-bb8c0271da88
Feed Name: TrustedSec blog
This report documents a local privilege escalation vulnerability in Intel Trusted Connect Service Client (Intel Management Engine Components v1822.12.0.1132) where the Windows msiexec repair operation sets permissive ACLs (Everyone: Full Control) on files under C:\ProgramData\Intel\iCLS Client\log. The researcher demonstrates exploiting this by creating a hardlink from a log filename to a service executable, triggering the msiexec ACL change to grant full control to the attacker, overwriting the service binary with a payload, and starting the service to create a new administrator account; Intel addressed the issue in version 1909.12.0.1236.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
