{"api_version":"1","generated_at":"2026-07-23T12:13:43+00:00","cve":"CVE-2020-23834","urls":{"html":"https://cve.report/CVE-2020-23834","api":"https://cve.report/api/cve/CVE-2020-23834.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-23834","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-23834"},"summary":{"title":"CVE-2020-23834","description":"Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\\bd\\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-09-04 04:15:00","updated_at":"2020-09-16 15:34:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/48789","name":"https://www.exploit-db.com/exploits/48789","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"BarracudaDrive v6.5 - Insecure Folder Permissions - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/boku7/BarracudaDrivev6.5-LocalPrivEsc","name":"https://github.com/boku7/BarracudaDrivev6.5-LocalPrivEsc","refsource":"MISC","tags":["Third Party Advisory"],"title":"GitHub - boku7/BarracudaDrivev6.5-LocalPrivEsc: Insecure Service File Permissions in bd service in Real Time Logics BarracudaDrive v6.5 allows local attackers to escalate privileges to admin via replacing the bd.exe file and restarting the computer where it will be run as 'LocalSystem' on the next startup automatically.","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-23834","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-23834","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"23834","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realtimelogic","cpe5":"barracudadrive","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"23834","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realtimelogic","cpe5":"barracudadrive","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-23834","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\\bd\\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/boku7/BarracudaDrivev6.5-LocalPrivEsc","refsource":"MISC","name":"https://github.com/boku7/BarracudaDrivev6.5-LocalPrivEsc"},{"refsource":"MISC","name":"https://www.exploit-db.com/exploits/48789","url":"https://www.exploit-db.com/exploits/48789"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AC:L/AV:L/A:H/C:H/I:H/PR:L/S:C/UI:N","version":"3.1"}}},"nvd":{"publishedDate":"2020-09-04 04:15:00","lastModifiedDate":"2020-09-16 15:34:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:realtimelogic:barracudadrive:6.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"23834","Ordinal":"185243","Title":"CVE-2020-23834","CVE":"CVE-2020-23834","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"23834","Ordinal":"1","NoteData":"Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\\bd\\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"23834","Ordinal":"2","NoteData":"2020-09-03","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"23834","Ordinal":"3","NoteData":"2020-09-03","Type":"Other","Title":"Modified"}]}}}