7.8
CVE-2020-23967
- EPSS 0.04%
- Veröffentlicht 08.03.2021 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:14:15
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drweb ≫ Security Space Version11.0
Drweb ≫ Security Space Version12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.065 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.