Smartfren Connex EC1261 contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by the application setting insecure file permissions on the installation directory. This may allow a local attacker to overwrite arbitrary files or libraries, which will allow them to escalate their privileges.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
OSVDB:
Authentication Required
Solution
OSVDB is not aware of a solution for this vulnerability.