Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elevated privileges.
                
            References
                    | Link | Resource | 
|---|---|
| http://cybereason.com | Vendor Advisory | 
| http://endpoint.com | Not Applicable | 
| https://www.cybereason.com/cybereason-vulnerability-disclosure | Vendor Advisory | 
| http://cybereason.com | Vendor Advisory | 
| http://endpoint.com | Not Applicable | 
| https://www.cybereason.com/cybereason-vulnerability-disclosure | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 05:18
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-01-20 21:15
Updated : 2025-04-03 18:15
NVD link : CVE-2020-25502
Mitre link : CVE-2020-25502
CVE.ORG link : CVE-2020-25502
JSON object : View
Products Affected
                cybereason
- endpoint_detection_and_response
 
CWE
                
                    
                        
                        CWE-427
                        
            Uncontrolled Search Path Element
