TROYANOSYVIRUS
Retour aux CVEs

CVE-2020-11613

HIGH
7.8

Description

Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on the system can replace binaries or plant malicious DLLs to obtain elevated, or different, privileges, depending on the context of the user that runs the application.

Details CVE

Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie6/11/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

mids\'_reborn_hero_designer_project:mids\'_reborn_hero_designer

Faiblesses (CWE)

CWE-427CWE-732

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.