← volver
CVE-2020-6021

CVE-2020-6021

EPSS 0.3%CWE-427
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 dic 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →