Executive brief
ArubaSign, a desktop application used for digital signing and document verification, contains a security flaw in its installation process. This flaw allows any user on a computer to replace the application's core files with malicious software. If an administrator subsequently runs the tampered application, the attacker could gain full control over the entire system and its data.
Technical details
A vulnerability classified as CWE-276 (Incorrect Default Permissions) exists in ArubaSign versions prior to v4.6.6. During installation, the application assigns excessive write permissions to the 'Everyone' group for the main executable and other program files located in C:\Program Files. A local, unprivileged attacker can exploit this by replacing legitimate binaries or components with malicious code. If the replaced file is later executed by a user with higher privileges (such as an Administrator or the SYSTEM account), the attacker can achieve arbitrary code execution with elevated privileges, leading to a full system compromise. Users should update to version 4.6.6 or later to resolve this issue.
Affected products
- Aruba ArubaSign prior to v4.6.6
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory