Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
3CX Phone 授权问题漏洞
Vulnerability Description
3CX Phone是一款基于软件的专用分支交换机。该产品可与基于SIP标准的IP电话、SIP中继和VoIP网关配合使用,提供完整的通信解决方案。 3CX Phone 15版本(Windows)中存在安全漏洞,该漏洞源于程序为‘%PROGRAMDATA%3CXPhone for WindowsPhoneApp’安装路径分配了不安全的权限。攻击者可利用该漏洞提升权限。
CVSS Information
N/A
Vulnerability Type
N/A