CVE-2020-23967

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITYSYSTEM due to insufficient control during autoupdate.
References
Link Resource
https://habr.com/ru/company/pm/blog/509592/ Exploit Third Party Advisory
https://amonitoring.ru/article/drweb/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=q7Kqi7kE59U Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:drweb:security_space:12.0:*:*:*:*:*:*:*
cpe:2.3:a:drweb:security_space:11.0:*:*:*:*:*:*:*

Information

Published : 2021-03-08 03:15

Updated : 2021-03-11 08:38


NVD link : CVE-2020-23967

Mitre link : CVE-2020-23967

Products Affected
No products.
CWE
CWE-347

Improper Verification of Cryptographic Signature