7.8

CVE-2020-23740

In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DrivergeniusDrivergenius Version9.61.5480.28
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.249
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://www.drivergenius.com/
Product
https://github.com/y5s5k5/CVE-2020-23740
Third Party Advisory
Broken Link
https://github.com/y5s5k5/POCtemp8
Third Party Advisory
Broken Link
https://www.cnvd.org.cn/flaw/show/2438470
Third Party Advisory