CVE-2020-13532: Critical severity dreamreport remote connector vulnerability
Published Apr 9, 2021
·Updated
A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Dreamreport Dream Report=5_r20-2
Event History
Apr 9, 2021
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13532?
The severity of CVE-2020-13532 is critical with a CVSS score of 7.8.
2
How can I exploit the privilege escalation vulnerability in Dream Report 5 R20-2?
An attacker can provide a malicious file to replace the Syncfusion Dashboard Service service binary and escalate privileges to NT SYSTEM.
3
Is Dream Report 5 R20-2 affected by CVE-2020-13532?
Yes, Dream Report 5 R20-2 is affected by the privilege escalation vulnerability described in CVE-2020-13532.
4
What is the CWE associated with CVE-2020-13532?
The CWE associated with CVE-2020-13532 is CWE-276.