CVE-2020-26894
Summary
| CVE | CVE-2020-26894 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-08 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run the malicious "cmd.exe". |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Faulknermedia | Wildlife Issues In The New Millennium | 18.0.160 | All | All | All |
| Application | Faulknermedia | Wildlife Issues In The New Millennium | 18.0.160 | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-26894 Privilege Escalation Vulnerability in LiveCode v9.6.1 Programming Language | MISC | john-woodman.com | Exploit, Third Party Advisory |
| LiveCode Quality Control Center | MISC | quality.livecode.com | Third Party Advisory |
| [[ Bug 22942 ]] Ensure the shellcommand defaults to COMSPEC on Windows by livecodepanos · Pull Request #7454 · livecode/livecode · GitHub | MISC | github.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.