WD Discovery, SanDisk ibi, and SanDisk Flashback - Local Escalation of Privileges


WDC Tracking Number: WDC-19015
Product Line/Web:  WD Discovery, SanDisk ibi, SanDisk Flashback
Published: November 22, 2019

Last Updated: November 22, 2019

Description

WD Discovery, SanDisk ibi, and SanDisk Flashback were vulnerable to a local escalation of privilege.

Product Impact
Last Updated
WD Discovery Mac
November 22, 2019
WD Discovery Windows
November 22, 2019
ibi Version
November 22, 2019
Flashback for Mac
November 22, 2019
Flashback for Win
November 22, 2019

Advisory Summary

An API intended to support automatic software update incorrectly allowed arbitrary command execution. Additionally, privileged executables used to communicate with hardware devices were installed with incorrect permissions. The affected API has been removed and the privileged executables have been moved to a restricted directory.

Compare