Description
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Severity (CVSS)
| Base score | 8.5 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- — CWE-732 Incorrect Permission Assignment for Critical Resource
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Cloud Foundry Foundation | bosh-windows-stemcell-builder | 0 to <2019.98 |
References
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.