CVE-2019-20456

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
16/02/2020
Last modified:
26/02/2020

Description

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:goverlan:client_agent:*:*:*:*:*:*:*:* 9.20.50 (excluding)
cpe:2.3:a:goverlan:reach_console:*:*:*:*:*:*:*:* 9.50 (excluding)
cpe:2.3:a:goverlan:reach_server:*:*:*:*:*:*:*:* 3.50 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*