CVE-2020-23967

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
References
Link Resource
https://amonitoring.ru/article/drweb/ Exploit Third Party Advisory
https://habr.com/ru/company/pm/blog/509592/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=q7Kqi7kE59U Exploit Third Party Advisory
https://amonitoring.ru/article/drweb/ Exploit Third Party Advisory
https://habr.com/ru/company/pm/blog/509592/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=q7Kqi7kE59U Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drweb:security_space:11.0:*:*:*:*:*:*:*
cpe:2.3:a:drweb:security_space:12.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:14

Type Values Removed Values Added
References () https://amonitoring.ru/article/drweb/ - Exploit, Third Party Advisory () https://amonitoring.ru/article/drweb/ - Exploit, Third Party Advisory
References () https://habr.com/ru/company/pm/blog/509592/ - Exploit, Third Party Advisory () https://habr.com/ru/company/pm/blog/509592/ - Exploit, Third Party Advisory
References () https://www.youtube.com/watch?v=q7Kqi7kE59U - Exploit, Third Party Advisory () https://www.youtube.com/watch?v=q7Kqi7kE59U - Exploit, Third Party Advisory

Information

Published : 2021-03-08 15:15

Updated : 2024-11-21 05:14


NVD link : CVE-2020-23967

Mitre link : CVE-2020-23967

CVE.ORG link : CVE-2020-23967


JSON object : View

Products Affected

drweb

  • security_space
CWE
CWE-347

Improper Verification of Cryptographic Signature