{"api_version":"1","generated_at":"2026-07-23T11:55:33+00:00","cve":"CVE-2020-7862","urls":{"html":"https://cve.report/CVE-2020-7862","api":"https://cve.report/api/cve/CVE-2020-7862.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7862","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7862"},"summary":{"title":"CVE-2020-7862","description":"A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2021-06-24 11:15:00","updated_at":"2022-09-20 19:04:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094","name":"https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094","refsource":"MISC","tags":[],"title":"KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://helpu.co.kr/customer/download.html","name":"https://helpu.co.kr/customer/download.html","refsource":"MISC","tags":[],"title":"원격지원 헬프유 - 다운로드","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7862","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7862","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks to Jeongun Back for reporting this vulnerability.","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"7862","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"helpu","cpe5":"helpuftclient","cpe6":"3.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7862","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"helpu","cpe5":"helpuftserver","cpe6":"3.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7862","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"helpu","cpe5":"helpuserver","cpe6":"1.0.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7862","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"helpu","cpe5":"helpuviewer","cpe6":"2018.5.21.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","DATE_PUBLIC":"2021-06-23T05:51:00.000Z","ID":"CVE-2020-7862","STATE":"PUBLIC","TITLE":"HelpU Overflow Vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"HelpuViewer.exe","version":{"version_data":[{"platform":"x86, x64","version_affected":"<=","version_name":"2018.5.21.0","version_value":"2020.11.20.0"}]}},{"product_name":"HelpuServer.exe","version":{"version_data":[{"platform":"x86, x64","version_affected":"<=","version_name":"1.0.0.2","version_value":"2020.11.20.0"}]}},{"product_name":"HelpuFTClient.dll","version":{"version_data":[{"platform":"x86, x64","version_name":"3.0.0.0","version_value":"2020.11.20.0"}]}},{"product_name":"HelpuFTServer.dll","version":{"version_data":[{"platform":"x86, x64","version_name":"3.0.0.0","version_value":"2020.11.20.0"}]}}]},"vendor_name":"Helpu,inc"}]}},"credit":[{"lang":"eng","value":"Thanks to Jeongun Back for reporting this vulnerability."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]},{"description":[{"lang":"eng","value":"CWE-120 Buffer Overflow"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094","name":"https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094"},{"refsource":"MISC","url":"https://helpu.co.kr/customer/download.html","name":"https://helpu.co.kr/customer/download.html"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-06-24 11:15:00","lastModifiedDate":"2022-09-20 19:04:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:helpu:helpuviewer:2018.5.21.0:*:*:*:*:windows:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:helpu:helpuserver:1.0.0.2:*:*:*:*:windows:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:helpu:helpuftclient:3.0.0.0:*:*:*:*:windows:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:helpu:helpuftserver:3.0.0.0:*:*:*:*:windows:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7862","Ordinal":"168145","Title":"CVE-2020-7862","CVE":"CVE-2020-7862","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7862","Ordinal":"1","NoteData":"A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7862","Ordinal":"2","NoteData":"2021-06-24","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7862","Ordinal":"3","NoteData":"2021-06-24","Type":"Other","Title":"Modified"}]}}}