Blog | G5 Cyber Security

QNAP QTS Domain Privilege Escalation Vulnerability

The vulnerability allows any local user, such as httpdusr used to run web application, to escalate to Domain Administrator if the NAS is a domain member. The affected component is the uLinux.conf configuration file, created with a world-readable permission used to store a Domain Administrator password. The issue involves all the QNAP NAS (all models and all versions) that are members of a Microsoft Active Directory and allows a local QTS admin user, or other low privileged user, to access configuration file that includes a bad crypted Microsoft domain administrator password.”]

Source: https://securityaffairs.co/wordpress/57387/hacking/qnap-qts-flaw.html

Exit mobile version