CVE-2020-5755

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2020
Last modified:
21/07/2021

Description

Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webroot:endpoint_agents:*:*:*:*:*:*:*:* 9.0.28.48 (excluding)


References to Advisories, Solutions, and Tools