8.8

CVE-2020-36161

An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a directory at the configuration file locations. When the Windows system restarts, a malicious OpenSSL engine could exploit arbitrary code execution as SYSTEM. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Veritas ≫ Aptare It Analytics Version 10.4.00 Update -
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch1
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch2
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch3
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch4
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch5
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch6
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch7
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.4.00 Update patch8
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.5.00 Update -
   Microsoft ≫ Windows Version -
Veritas ≫ Aptare It Analytics Version 10.5.00 Update patch1
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.336
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.veritas.com/content/support/en_US/security/VTS20-009
Vendor Advisory