关键漏洞信息 漏洞名称: BIND 9.10.5 - Unquoted Service Path Privilege Escalation 漏洞编号: EDB-ID: 42121 CVE: 2017-3141 作者与发表日期: Author: hyp3rlinx Date: 2017-06-05 漏洞影响: Platform: WINDOWS Vulnerable App: BIND9 v9.10.5 (x86/x64) 漏洞类型与严重性: Type: LOCAL Vulnerability Type: Privilege Escalation Severity: Medium 漏洞描述: BIND installs as a service with an unquoted service path, a local attacker can place a malicious executable file named "Program.exe" in the path of the service, leading to privilege escalation if the process runs under a different account. 补丁时间线: Vendor Notification: May 13, 2017 Vendor Confirm: May 14, 2017 Public Disclosure: June 4, 2017 披露来源: Link: http://hyp3rlinx.altervista.org/advisories/BIND9-PRIVILEGE-ESCALATION.txt