← Zuruck zu CVEs
CVE-2020-8884
HIGH8.8
Beschreibung
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht1/6/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
proofpoint:insider_threat_management
Schwachen (CWE)
CWE-502
Referenzen
https://www.proofpoint.com/us/blog(cve@mitre.org)
https://www.proofpoint.com/us/blog(af854a3a-2127-422b-91ae-364da2661108)
https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2020-0002(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.