25.04.2021Vulnerability discovered.
26.04.2021Vendor contacted.
26.04.2021Vendor responds with instructions to open a ticket at HackerOne.
26.04.2021ZSL creates a ticket on HackerOne, asking if this is something they can handle or is in scope.
26.04.2021HackerOne reviews the question.
26.04.2021HackerOne states that RCE due to BoF is in scope but because no PoC provided, closes the ticket.
28.04.2021ZSL provides PoC file.
28.04.2021HackerOne reopens the ticket, asking further details.
28.04.2021ZSL provides further details and video demonstrating the issue.
30.04.2021HackerOne states that folder CookedPCConsole is not writable for the Limited user. Administrator privilege is required to inject the payload, therefore, this privilege escalation scenario cannot be accepted as valid. For this scenario to be accepted as a valid RCE scenario, you must be able to inject the payload as a Limited User, and you can execute cmd.exe and demonstrate the privilege escalation scenario.
30.04.2021HackerOne closes the ticket and changes the status to Informative.
30.04.2021ZSL explains that there are insecure permissions on the folder that can allow payload injection and EoP. Further, through BoF (which is a vulnerability) code execution is possible. ZSL didn't want to provide weaponized PoC where calc.exe pops, stating that it is sufficient to confirm the issue with provided PoC UPK crash file.
30.04.2021Public security advisory released.