# Exploit Title: Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission # Date: 21.12.2020 # Exploit Author: Adrian Bondocea # Vendor Homepage: https://www.fluentd.org/ # Software Link: https://td-agent-package-browser.herokuapp.com/4/windows # Version: icacls C:\opt\td-agent\bin C:\opt\td-agent\bin BUILTIN\Administrators:(I)(OI)(CI)(F) NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F) BUILTIN\Users:(I)(OI)(CI)(RX) NT AUTHORITY\Authenticated Users:(I)(M) NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(IO)(M) Successfully processed 1 files; Failed processing 0 files Vulnerable service: PS C:\opt\td-agent\bin> get-service fluentdwinsvc Status Name DisplayName ------ ---- ----------- Running fluentdwinsvc Fluentd Windows Service Service Path: "C:/opt/td-agent/bin/ruby.exe" -C t"C:/opt/td-agent/lib/ruby/gems/2.7.0/gems/fluentd-1.11.2/lib/fluent/command/.." winsvc.rb --service-name fluentdwinsvc