Vulnerable Systems:
* RubyInstaller 1.9.3-p194 and prior
A local attacker can exploit this issue to gain escalated privileges. This may aid in further attacks.
A security issue has been discovered in RubyInstaller, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
The security issue is caused due to the application setting insecure file system permissions on the installation directory and can be exploited to overwrite files (e.g. "C:\Ruby193\bin") and execute programs with privileges of another user.
The security issue is confirmed in version 1.9.3-p194. Other versions may also be affected.