CVE-2016-20025 PUBLISHED

ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure Permissions

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 15.03.2026

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for privilege escalation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor ZKTeco Inc.
Product ZKTeco ZKAccess Professional
Versions
  • Version 3.5.3 (Build 0005) is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Files or Directories Accessible to External Parties CWE