module
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Disclosed |
---|
Feb 25, 2020 |
Disclosed
Feb 25, 2020
Description
Druva inSync client for Windows exposes a network service on TCP
port 6064 on the local network interface. inSync versions 6.6.3
and prior do not properly validate user-supplied program paths
in RPC type 5 messages, allowing execution of arbitrary commands
as SYSTEM.
This module has been tested successfully on inSync versions
6.5.2r99097 and 6.6.3r102156 on Windows 7 SP1 (x64).
port 6064 on the local network interface. inSync versions 6.6.3
and prior do not properly validate user-supplied program paths
in RPC type 5 messages, allowing execution of arbitrary commands
as SYSTEM.
This module has been tested successfully on inSync versions
6.5.2r99097 and 6.6.3r102156 on Windows 7 SP1 (x64).

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.