{"id":"CVE-2016-8742","details":"The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.","modified":"2026-07-08T15:09:46.285755Z","published":"2018-02-12T17:29:00.277Z","references":[{"type":"ADVISORY","url":"http://mail-archives.apache.org/mod_mbox/couchdb-dev/201612.mbox/%3C825F65E1-0E5F-4E1F-8053-CF2C6200C526%40apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94766"},{"type":"ADVISORY","url":"https://www.exploit-db.com/exploits/40865/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/couchdb","events":[{"introduced":"cb02b9b812174609403d67f60c314959388ba06c"},{"last_affected":"cb02b9b812174609403d67f60c314959388ba06c"}],"database_specific":{"cpe":"cpe:2.3:a:apache:couchdb:2.0.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.0.0"}],"source":"CPE_STRING"}}],"versions":["2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8742.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}