CVE-2020-17381

An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the %SYSTEMDRIVE%totalcmdTOTALCMD64.EXE binary.
References
Link Resource
https://github.com/an0ry/advisories/blob/main/CVE-2020-17381.md Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:ghisler:total_commander:9.51:*:*:*:*:*:*:*

Information

Published : 2020-10-21 07:15

Updated : 2020-10-30 01:35


NVD link : CVE-2020-17381

Mitre link : CVE-2020-17381

Products Affected
No products.
CWE
CWE-276

Incorrect Default Permissions