CVE-2020-6012
CVE-2020-6012
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
04 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.
Affected products
n/a · ZoneAlarm Anti-RansomwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →