Impact
The vulnerability stems from incorrect permission assignments in the BOSH.Utils.psm1 module, allowing a low‑privilege authenticated user to overwrite critical service executables C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe. When either service is restarted or the host reboots, the modified binary runs under the SYSTEM account, granting the attacker complete control of the host. This escalation can compromise all system functions and data.
Affected Systems
bosh-windows-stemcell-builder from Cloud Foundry Foundation, versions prior to v2019.98. The flaw is present in all builds lacking the ACL correction applied in v2019.98 and earlier releases.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑impact local privilege escalation that requires only local authentication. With an EPSS score of less than 1%, exploitation is currently considered unlikely, and the vulnerability is not listed in CISA KEV, so no publicly documented exploitation exists yet. An attacker who can write to the service executables must then trigger a service restart or system reboot; no remote network access is required for exploitation.
OpenCVE Enrichment