Email-Worm.Win32.Sircam.eb Insecure Permissions

Email-Worm.Win32.Sircam.eb Insecure Permissions

Email-Worm.Win32.Sircam.eb malware suffers from an insecure permissions vulnerability.

1
2
3
4
5
6
7
Exploit/PoC:
C:\>cacls \Windupdt
C:\Windupdt BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C