Vulnerability Details CVE-2016-6914
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.8%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2016-6914
-
cpe:2.3:a:ui:unifi_video:2.1.3
-
cpe:2.3:a:ui:unifi_video:3.0.1
-
cpe:2.3:a:ui:unifi_video:3.1.5
-
cpe:2.3:a:ui:unifi_video:3.7.0
-
cpe:2.3:a:ui:unifi_video:3.7.1
-
cpe:2.3:a:ui:unifi_video:3.7.2
-
cpe:2.3:a:ui:unifi_video:3.7.3
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista