CyberRota Analysis
AI-GeneratedA vulnerability exists in the BOSH-Ecosystem bosh-windows-stemcell-builder, where low-privilege authenticated users can exploit incorrect permission assignments to overwrite critical executables, specifically C:\bosh\service_wrapper.exe and C:\bosh\bosh-agent.exe. This flaw allows attackers to escalate their privileges to NT AUTHORITY\SYSTEM upon the next service restart or system reboot, potentially granting them full control over the host. Organizations utilizing affected versions prior to v2019.98 should prioritize remediation to mitigate the risk of unauthorized access and system compromise.
Original NVD Description
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.