CVE-2020-23967

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
References
Link Resource
https://amonitoring.ru/article/drweb/ Exploit Third Party Advisory
https://habr.com/ru/company/pm/blog/509592/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=q7Kqi7kE59U Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drweb:security_space:11.0:*:*:*:*:*:*:*
cpe:2.3:a:drweb:security_space:12.0:*:*:*:*:*:*:*

History

11 Mar 2021, 20:38

Type Values Removed Values Added
References (MISC) https://www.youtube.com/watch?v=q7Kqi7kE59U - (MISC) https://www.youtube.com/watch?v=q7Kqi7kE59U - Exploit, Third Party Advisory
References (MISC) https://amonitoring.ru/article/drweb/ - (MISC) https://amonitoring.ru/article/drweb/ - Exploit, Third Party Advisory
References (MISC) https://habr.com/ru/company/pm/blog/509592/ - (MISC) https://habr.com/ru/company/pm/blog/509592/ - Exploit, Third Party Advisory
CWE CWE-347
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:a:drweb:security_space:12.0:*:*:*:*:*:*:*
cpe:2.3:a:drweb:security_space:11.0:*:*:*:*:*:*:*

08 Mar 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-08 15:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-23967

Mitre link : CVE-2020-23967

CVE.ORG link : CVE-2020-23967


JSON object : View

Products Affected

drweb

  • security_space
CWE
CWE-347

Improper Verification of Cryptographic Signature