CVE-2020-3927

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:changingtec:servisign:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

25 May 2022, 19:28

Type Values Removed Values Added
References (MISC) https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - (MISC) https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce - Third Party Advisory

Information

Published : 2020-02-03 11:15

Updated : 2023-12-10 13:13


NVD link : CVE-2020-3927

Mitre link : CVE-2020-3927

CVE.ORG link : CVE-2020-3927


JSON object : View

Products Affected

changingtec

  • servisign

microsoft

  • windows
CWE
CWE-552

Files or Directories Accessible to External Parties