CVE-2020-8884
Summary
| CVE | CVE-2020-8884 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-06 14:15:00 UTC |
| Updated | 2021-01-13 19:21:00 UTC |
| Description | rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proofpoint | Insider Threat Management | All | All | All | All |
| Application | Proofpoint | Insider Threat Management | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PFPT-SA-2020-0002 | Proofpoint US | CONFIRM | www.proofpoint.com | Vendor Advisory |
| Cybersecurity Intelligence, News & Insights | Proofpoint US | MISC | www.proofpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.