CVE-2020-13533
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation files and escalate privileges when a new user logs in and uses the application.
Se presenta una vulnerabilidad de escalada de privilegios en Dream Report versión 5 R20-2. En la configuración predeterminada, las siguientes claves de registro, que hacen referencia a binarios con permisos débiles, pueden ser abusadas por parte de atacantes para hacer efectivamente un "backdoor" de los archivos de instalación y escalar los privilegios cuando un nuevo usuario inicia sesión y usa la aplicación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-26 CVE Reserved
- 2021-04-09 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-08-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1146 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dreamreport Search vendor "Dreamreport" | Dream Report Search vendor "Dreamreport" for product "Dream Report" | 5_r20-2 Search vendor "Dreamreport" for product "Dream Report" and version "5_r20-2" | - |
Affected
|