The installer of 3CX Softphone does a couple of dangerous crazy things that lead to a privilege escalation vulnerability. The first unusual practice is installing the executable to a folder in C:\ProgramData instead of C:\ProgramFiles as normal. This means 3CX Softphone is not even executable with Software Restriction Policies (SRP) enabled with just the defaults. The next catastrophic mishap is creating the folder 3CXPhone for Windows with full access permission for EVERYONE. Last but not least, the installer creates an autostart Target for 3CXPhone for Windows. This means as soon as an user with administrative privileges logs in, 3CXWin8Phone.exe is executed as well. Guess what happens if any user replaces this executable.
I assume it is set up in this way to allow trivial automatic updates for any user because the developers just don't know any better. My only question is: WTF?
I assume it is set up in this way to allow trivial automatic updates for any user because the developers just don't know any better. My only question is: WTF?