CVE-2020-13533: Critical severity dreamreport remote connector vulnerability
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation files and escalate privileges when a new user logs in and uses the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13533?
CVE-2020-13533 is classified as a privilege escalation vulnerability.
How do I fix CVE-2020-13533?
To fix CVE-2020-13533, ensure you update Dream Report to the latest version or adjust the permissions on the affected registry keys.
What products are affected by CVE-2020-13533?
CVE-2020-13533 affects Dream Report version 5 R20-2.
What is the impact of CVE-2020-13533?
The impact of CVE-2020-13533 allows attackers to escalate privileges and potentially backdoor the installation files.
Who can exploit CVE-2020-13533?
Attackers with access to the default configuration can exploit CVE-2020-13533 to escalate their privileges.