CVE-2019-20456
Summary
| CVE | CVE-2019-20456 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-16 19:15:00 UTC |
| Updated | 2020-02-26 15:10:00 UTC |
| Description | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. |
Risk And Classification
Problem Types: CWE-426
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Goverlan | Client Agent | All | All | All | All |
| Application | Goverlan | Client Agent | All | All | All | All |
| Application | Goverlan | Reach Console | All | All | All | All |
| Application | Goverlan | Reach Console | All | All | All | All |
| Application | Goverlan | Reach Server | All | All | All | All |
| Application | Goverlan | Reach Server | All | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory GOVSA.2019.1028.1 - Untrusted Search Path - Goverlan Reach Remote Support | MISC | www.goverlan.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.