CVE-2020-10733

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

History

06 Jan 2022, 14:19

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20201001-0006/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20201001-0006/ - Third Party Advisory

Information

Published : 2020-09-16 15:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-10733

Mitre link : CVE-2020-10733

CVE.ORG link : CVE-2020-10733


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-426

Untrusted Search Path