← Voltar para CVEs
CVE-2020-36938
HIGH8.8
Descricao
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly permissive access controls to potentially modify critical DLLs and executable files in the WinAVR installation directory.
Detalhes CVE
Pontuacao CVSS v3.18.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado1/27/2026
Ultima modificacao1/29/2026
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-732
Referencias
https://sourceforge.net/projects/winavr/(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/49379(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/winavr-version-insecure-folder-permissions(disclosure@vulncheck.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.