.
 
WD Discovery, SanDisk ibi, and SanDisk Flashback - Local Escalation of Privileges
WDC Tracking Number: WDC-19015
Product Line/Web:  WD Discovery, SanDisk ibi, SanDisk Flashback
Published: November 22, 2019
Last Updated: November 22, 2019
Description
WD Discovery, SanDisk ibi, and SanDisk Flashback were vulnerable to a local escalation of privilege.
Product Impact
      
      Last Updated
   WD Discovery Mac
      
      November 22, 2019
   WD Discovery Windows
      
      November 22, 2019
   ibi Version
      
      November 22, 2019
   Flashback for Mac
      
      November 22, 2019
   Flashback for Win
      
      November 22, 2019
   Advisory Summary
An API intended to support automatic software update incorrectly allowed arbitrary command execution. Additionally, privileged executables used to communicate with hardware devices were installed with incorrect permissions. The affected API has been removed and the privileged executables have been moved to a restricted directory.