Security Researchers Baby Cooke and Adeeb Shah have reported on exploitdb site, then BarracudaDrive is part of vulnerability.

BarracudaDrive Think of an application server as a GUI engine that is connected to a remote display with applications running in the server dynamically creating the user interface and presenting the user interface in, for example, a browser. A web server is limited to presenting static (pre-designed) web pages and is consequently of little value or no value for designing GUI applications since a GUI typically changes the look and behavior when used by a client. Some web servers allow extensions such as CGI and other means for managing dynamic content. These extensions typically limit the GUI designer and make it time consuming and difficult to design GUI applications.

According to the same authors: ” Insecure Service File Permissions in bd service in Real Time Logic BarracudaDrive v6.5 allows local low-privilege attacker to escalate privileges to admin via replacing the bd.exe file and restarting the computer where the malicious code will be executed as ‘LocalSystem’ on the next startup.”, says the report.

There is no update available from vendor to fix this issue.

error: Content is protected !!