Vulnerable Systems:
* PassGo SSO Plus version 2.1.0.32
* Other versions suspected.
The problem is that the application sets insecure default permissions (grants "Everyone" group "Full Control") on the "PassGo Technologies" directory and all child objects. This can be exploited to remove, manipulate, and replace any of the application's files.
Solution:
Set proper permissions on the application directory and all child objects.
Grant only trusted users access to affected systems.