CVE-2020-23967

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
References
Link Resource
https://amonitoring.ru/article/drweb/ Exploit Third Party Advisory
https://habr.com/ru/company/pm/blog/509592/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=q7Kqi7kE59U Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drweb:security_space:11.0:*:*:*:*:*:*:*
cpe:2.3:a:drweb:security_space:12.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-03-08 15:15

Updated : 2024-02-04 21:23


NVD link : CVE-2020-23967

Mitre link : CVE-2020-23967

CVE.ORG link : CVE-2020-23967


JSON object : View

Products Affected

drweb

  • security_space
CWE
CWE-347

Improper Verification of Cryptographic Signature