Photodex ProShow Producer contains a flaw that is triggered by the program setting the 'Full Control' permissions on the 'Everyone' group and its child objects by default. This may allow a local attacker to replace, remove, and manipulate arbitrary files.
Classification
Location:
Local Access Required
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
OSVDB:
Authentication Required
Solution
OSVDB is not aware of a solution for this vulnerability.