CVE-2020-8884

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*

History

13 Jan 2021, 19:21

Type Values Removed Values Added
CPE cpe:2.3:a:proofpoint:inside_threat_management:*:*:*:*:*:windows:*:* cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*

08 Jan 2021, 20:27

Type Values Removed Values Added
CPE cpe:2.3:a:proofpoint:inside_threat_management:*:*:*:*:*:windows:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 8.8
References (MISC) https://www.proofpoint.com/us/blog - (MISC) https://www.proofpoint.com/us/blog - Vendor Advisory
References (CONFIRM) https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2020-0002 - (CONFIRM) https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2020-0002 - Vendor Advisory
CWE CWE-502

06 Jan 2021, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-06 14:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-8884

Mitre link : CVE-2020-8884

CVE.ORG link : CVE-2020-8884


JSON object : View

Products Affected

proofpoint

  • insider_threat_management
CWE
CWE-502

Deserialization of Untrusted Data