01642 06 11 11 Arrange Call

Local Privilege Escalation Vulnerability in Advantech WebAccess/SCADA 9.0.1 via PostgreSQL Executable

CVE-2020-13551 · HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2020-13551

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.