Executive brief
Apache Lounge's Windows distribution of Apache HTTP Server installs with overly permissive folder permissions that allow authenticated local users to modify critical files. An attacker with local access can exploit this to replace legitimate binaries or configuration files, potentially executing malicious code or disrupting the web server's operation.
Technical details
The Apache Lounge Windows build sets insecure NTFS permissions on its default installation directory (C:\) that grant write access to the Authenticated Users group. An authenticated local attacker can exploit this to perform privilege escalation or arbitrary code execution by modifying Apache binaries, modules, or configuration files. This is a local privilege escalation vulnerability requiring existing system access.
Affected products
- Apache Lounge Apache HTTP Server
Timeline
- 2026-09-22: disclosed