CVE-2020-11613
Summary
| CVE | CVE-2020-11613 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-11 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on the system can replace binaries or plant malicious DLLs to obtain elevated, or different, privileges, depending on the context of the user that runs the application. |
Risk And Classification
Problem Types: CWE-427 | CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mids Reborn Hero Designer Project | Mids Reborn Hero Designer | 2.6.0.7 | All | All | All |
| Application | Mids Reborn Hero Designer Project | Mids Reborn Hero Designer | 2.6.0.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/Crytilis/mids-reborn-hero-designer/releases | MISC | github.com | Release Notes, Third Party Advisory |
| Mids Reborn Vulnerabilities - CVE-2020-11613 & CVE-2020-11614 | doyler.net | MISC | www.doyler.net | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.