CVE-2020-7867

An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator.
Configurations

Configuration 1 (hide)

cpe:2.3:a:helpu:helpuviewer:2018.5.21.0:*:*:*:*:windows:*:*

History

29 Oct 2021, 01:20

Type Values Removed Values Added
CPE cpe:2.3:a:helpu:helpuviewer:2018.5.21.0:*:*:*:*:windows:*:*
References (MISC) https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36303 - (MISC) https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36303 - Third Party Advisory
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8

27 Oct 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-27 01:15

Updated : 2024-02-04 22:08


NVD link : CVE-2020-7867

Mitre link : CVE-2020-7867

CVE.ORG link : CVE-2020-7867


JSON object : View

Products Affected

helpu

  • helpuviewer
CWE
CWE-20

Improper Input Validation