CVE-2020-11613
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on the system can replace binaries or plant malicious DLLs to obtain elevated, or different, privileges, depending on the context of the user that runs the application.
Reborn Hero Designer de Mids versión 2.6.0.7, presenta una vulnerabilidad de elevación de privilegios debido a que se establecen permisos predeterminados y no seguros para la carpeta de instalación. Por defecto, el grupo Authenticated Users posee permisos Modify para la carpeta de instalación. Debido a esto, cualquier usuario en el sistema puede reemplazar los archivos binarios o plantar DLLs maliciosas para obtener privilegios elevados o diferentes, dependiendo del contexto del usuario que ejecuta la aplicación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-07 CVE Reserved
- 2020-06-11 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-427: Uncontrolled Search Path Element
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/Crytilis/mids-reborn-hero-designer/releases | Release Notes |
URL | Date | SRC |
---|---|---|
https://www.doyler.net/security-not-included/mids-reborn-vulnerabilities | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mids\' Reborn Hero Designer Project Search vendor "Mids\' Reborn Hero Designer Project" | Mids\' Reborn Hero Designer Search vendor "Mids\' Reborn Hero Designer Project" for product "Mids\' Reborn Hero Designer" | 2.6.0.7 Search vendor "Mids\' Reborn Hero Designer Project" for product "Mids\' Reborn Hero Designer" and version "2.6.0.7" | - |
Affected
|