Impact
The vulnerability arises from the default installation directory of the Apache Lounge Windows distribution of Apache HTTP Server, which is placed on the C:\ drive and inherits write permissions for Authenticated Users. This flaw lets any local authenticated user create or modify files in the installation directory, potentially allowing the alteration of server configuration files or the deployment of malicious executables. The result is that an attacker could gain the ability to run arbitrary code on the server or alter its behavior, compromising confidentiality, integrity, and availability. The weakness aligns with improper permission assignments (CWE‑732) and improper access control (CWE‑284).
Affected Systems
Apache Lounge Windows distribution of Apache HTTP Server is affected. No specific version numbers are disclosed. The issue is tied to installations that use the default C:\ path with its uncontrolled permissions.
Risk and Exploitability
The attack vector is local and requires an authenticated user account that can write to the installation directory. Because the flaw permits modification of critical server files, successful exploitation can lead to arbitrary code execution. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the severity of the potential impact remains substantial. The risk is high for systems where the installation path is left at the default location and where Authenticated Users have write access.
OpenCVE Enrichment