7.2
CVE-2020-1988
- EPSS 0.13%
- Veröffentlicht 08.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:47
- Quelle psirt@paloaltonetworks.com
- CVE-Watchlists
- Unerledigt
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Globalprotect SwPlatformwindows Version >= 4.1.0 < 4.1.13
Paloaltonetworks ≫ Globalprotect SwPlatformwindows Version >= 5.0.0 < 5.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.333 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| psirt@paloaltonetworks.com | 4.2 | 0.8 | 3.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.