A local privilege escalation vulnerability has been disclosed in Royal Server version 5.04.50529.0 by the 0day Rubbish Research Team. The flaw, categorized under CWE-250, allows authenticated scripts to execute as LocalSystem on the management gateway host. This vulnerability carries a CVSS score of 7.2, indicating a high severity risk for environments utilizing this management software.
While exploiting the vulnerability requires a valid authenticated session or admin credentials, the resulting impact allows for full system control without credential override. The vendor has been notified, and a CVE identifier is currently pending. Technical analysis and proof-of-concept materials have been made public as part of an ongoing disclosure series.
Top comments (0)