CVE-2020-9331
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space.
CryptoPro CSP versiones hasta 5.0.0.10004 en plataformas de 32 bits, permite una Escalada de Privilegios Locales (por usuarios locales con el derecho SeChangeNotifyPrivilege) porque la entrada en modo de usuario es manejada inapropiadamente durante la creación del proceso. Un atacante puede escribir datos arbitrarios en una ubicación arbitraria en el espacio de direcciones del kernel
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-02-21 CVE Reserved
- 2020-10-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.youtube.com/watch?v=b5vPDmMtzwQ | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cryptopro Search vendor "Cryptopro" | Csp Search vendor "Cryptopro" for product "Csp" | < 5.0.0.10004 Search vendor "Cryptopro" for product "Csp" and version " < 5.0.0.10004" | x86 |
Affected
|