Junglewise Threat Intelligence

CVE-2016-20025: ZKTeco ZKAccess Professional privilege escalation via insecure file permissions

CVE-2016-20025 · Severity: high · CVSS 8.8 · Published 2026-03-16

Vendors: Zkteco.

Executive brief

ZKTeco ZKAccess Professional is a desktop software suite used to manage physical access control readers and employee attendance reports. A security flaw in the software's installation allows any standard user on the system to modify or replace the application's executable files. An attacker could use this to plant malicious code that runs with higher system privileges, potentially leading to a full takeover of the computer managing the building's security infrastructure.

Technical details

ZKTeco ZKAccess Professional 3.5.3 (Build 0005) suffers from an insecure file permission configuration (CWE-552) where the 'Modify' (M) flag is granted to the 'Authenticated Users' group for the application directory. This allows a low-privileged local or network-authenticated user to replace legitimate service binaries or executables with malicious code. Upon execution by a higher-privileged user or the system, the attacker's code runs with elevated privileges, leading to full system compromise. The vulnerability was verified on Windows 7 environments using the icacls utility to confirm improper inheritance and permission assignments.

Affected products

  • ZKTeco ZKAccess Professional 3.5.3 (Build 0005) and earlier

Timeline

  • 2016-07-18: disclosed: Vulnerability discovered by Zero Science Lab
  • 2016-08-31: advisory: Public advisory and exploit released by Zero Science Lab (ZSL-2016-5361)
  • 2026-03-16: other: CVE-2016-20025 assigned/published via VulnCheck

References