Discover the vulnerability in Unitrends Backup (UB) versions before 10.0.0 allowing remote attackers to elevate user privileges. Learn how to mitigate this security risk.
A vulnerability in the session logic of Unitrends Backup (UB) versions prior to 10.0.0 allows remote attackers to elevate privileges from low to root.
Understanding CVE-2017-12479
This CVE discloses a security flaw in Unitrends Backup (UB) that enables the exploitation of the LOGDIR environment variable to escalate user privileges.
What is CVE-2017-12479?
The vulnerability in Unitrends Backup (UB) versions before 10.0.0 permits the elevation of low-privilege user rights to root privileges through the manipulation of the LOGDIR environment variable during a web session.
The Impact of CVE-2017-12479
This vulnerability allows remote attackers with low-privilege credentials to execute unrestricted root-level commands, posing a significant security risk to affected systems.
Technical Details of CVE-2017-12479
Unitrends Backup (UB) vulnerability details:
Vulnerability Description
The flaw in the session logic of Unitrends Backup (UB) versions prior to 10.0.0 enables the unauthorized elevation of user privileges using the LOGDIR environment variable during a web session.
Affected Systems and Versions
Exploitation Mechanism
Remote attackers with low-privilege credentials can exploit the vulnerability by manipulating the LOGDIR environment variable during a web session to gain root privileges and execute arbitrary commands.
Mitigation and Prevention
Steps to address CVE-2017-12479:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates