CVE-2020-21046

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.
Configurations

Configuration 1 (hide)

cpe:2.3:a:softonic:eagleget:*:*:*:*:*:*:*:*

History

25 Jul 2022, 09:33

Type Values Removed Values Added
CPE cpe:2.3:a:eagleget_project:eagleget:*:*:*:*:*:*:*:* cpe:2.3:a:softonic:eagleget:*:*:*:*:*:*:*:*

05 Jul 2022, 19:47

Type Values Removed Values Added
CWE CWE-269
References (MISC) https://medium.com/@n1pwn/local-privilege-escalation-in-eagleget-1fde79fe47c0 - (MISC) https://medium.com/@n1pwn/local-privilege-escalation-in-eagleget-1fde79fe47c0 - Exploit, Third Party Advisory
References (MISC) http://eagleget.com - (MISC) http://eagleget.com - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:a:eagleget_project:eagleget:*:*:*:*:*:*:*:*

24 Jun 2022, 16:51

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-24 16:15

Updated : 2024-02-04 22:29


NVD link : CVE-2020-21046

Mitre link : CVE-2020-21046

CVE.ORG link : CVE-2020-21046


JSON object : View

Products Affected

softonic

  • eagleget
CWE
CWE-269

Improper Privilege Management