BulletProof FTP Server Privilege Escalation Vulnerability
28 Apr. 2005
Summary
"BulletProof FTP Server is the most simple and powerful FTP server to install and manage. Total control over connected users and where your files go. All features available from an easy to use graphical interface! The most BulletProof way to distribute files."
When the BPFTPServer service is installed and running as LocalSystem it is possible to manipulate the administrative interface in such a way that it will allow a local user to escalate his privileges to that of the LocalSystem account.
Credit:
The information has been provided by Reed Arvin.