CVE-2020-24955
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.
SUPERAntiSyware Professional X Trial versión 10.0.1206, es vulnerable a una escalada de privilegios local porque permite a usuarios no privilegiado restaurar una DLL maliciosa de la cuarentena en la carpeta system32 por medio de una unión de directorio NTFS, como es demostrado por un archivo ualapi.dll diseñado que es detectado como malware
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-08-28 CVE Reserved
- 2020-09-01 CVE Published
- 2020-09-02 First Exploit
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/b1nary0x1 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/b1nary0x1/CVE-2020-24955 | 2020-09-02 | |
https://github.com/nmht3t/CVE-2020-24955 | 2020-09-02 | |
https://www.youtube.com/watch?v=jdcqbev-H5I | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Superantispyware Search vendor "Superantispyware" | Professional X Search vendor "Superantispyware" for product "Professional X" | < 10.0.1206 Search vendor "Superantispyware" for product "Professional X" and version " < 10.0.1206" | trial |
Affected
|