Impact
The vulnerability arises from improper write permissions on the directory C:\\ProgramData\\Maono used by the MaonoAiServices Windows service in Maono Link 3.8.13. A standard user can write arbitrary files to this location, enabling the creation of malicious executables or scripts that are run with elevated privileges when the service processes them. This results in privilege escalation from a normal user account to full administrative rights on the host system.
Affected Systems
Affected products include Maono Link from vendor Maono, specifically version 3.8.13. The issue was fixed in version 4.0.80, so any installations >=4.0.80 are not affected.
Risk and Exploitability
The CVSS score is 8.4, indicating high severity. EPSS is not provided, and the vulnerability is not listed in CISA's KEV catalog. The flaw is local, requiring a user account that has standard privileges on the machine. An attacker could exploit this by creating malicious files under the vulnerable directory. A local administrator or a user maliciously leveraging this can gain full administrative rights, enabling any subsequent actions.
OpenCVE Enrichment