CVE-2020-16268
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may craft a .reg file in a specific location that will be able to write to any registry key as an elevated user.
El instalador MSI en 1E Client versiones 4.1.0.267 y 5.0.0.745, permite a los usuarios autenticados remotos y a los usuarios locales obtener privilegios elevados por medio de la opción de reparación. Esto se aplica a instalaciones que tienen un TRANSFORM (MST) con la opción de deshabilitar la instalación del módulo Nomad. Un atacante puede crear un archivo .reg en una ubicación específica que podrá escribir en cualquier clave de registro como un usuario elevado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-03 CVE Reserved
- 2020-12-29 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
1e Search vendor "1e" | Client Search vendor "1e" for product "Client" | 4.1.0.267 Search vendor "1e" for product "Client" and version "4.1.0.267" | windows |
Affected
| ||||||
1e Search vendor "1e" | Client Search vendor "1e" for product "Client" | 5.0.0.745 Search vendor "1e" for product "Client" and version "5.0.0.745" | windows |
Affected
|