0day Rubbish Research Team has disclosed a high-severity local privilege escalation (LPE) vulnerability in Royal Server version 5.04.50529.0. The vulnerability, tracked under CWE-250, allows authenticated scripts to execute as LocalSystem on the management gateway host without requiring credential override. This flaw poses a significant risk as it permits users with valid administrative sessions to escalate their privileges to the highest level on the target system.
The exploit carries a CVSS score of 7.2, reflecting its impact on confidentiality, integrity, and availability. While the vendor has been notified and a CVE ID is currently pending, the research team has released a full technical analysis and a proof-of-concept via their blog and GitHub repository. This disclosure is part of an ongoing series of security research by the 0day Rubbish team.
Top comments (0)