CVE-2020-13177
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
11/08/2020
Last modified:
13/08/2020
Description
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:teradici:graphics_agent:*:*:*:*:*:windows:*:* | 20.04.1 (excluding) | |
| cpe:2.3:a:teradici:pcoip_standard_agent:*:*:*:*:*:windows:*:* | 20.04.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



