CVE-2020-12473: Critical severity mono vulnerability
Published Apr 29, 2020
·Updated
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.
Affected Software
1 affected component
Mono MonoX<=5.1.40.5152
Event History
Apr 29, 2020
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12473?
CVE-2020-12473 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2020-12473?
To fix CVE-2020-12473, ensure you revert any changed settings in the Converter Executable field back to ffmpeg.exe.
3
Who is affected by CVE-2020-12473?
CVE-2020-12473 affects all versions of MonoX up to and including 5.1.40.5152.
4
What is the impact of CVE-2020-12473?
The impact of CVE-2020-12473 allows unauthorized execution of arbitrary programs on the server.
5
Is physical access required to exploit CVE-2020-12473?
No, physical access is not required; an attacker can exploit CVE-2020-12473 remotely through the admin interface.