CVE-2020-13866: High severity qbik wingate vulnerability
Published Jun 8, 2020
·Updated
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
Affected Software
1 affected component
Qbik WinGate=9.4.1.5998
Event History
Jun 8, 2020
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13866?
CVE-2020-13866 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2020-13866?
To fix CVE-2020-13866, change the permissions of the WinGate installation directory to restrict unauthorized access.
3
Who is affected by CVE-2020-13866?
CVE-2020-13866 affects users of WinGate version 9.4.1.5998.
4
What type of vulnerability is CVE-2020-13866?
CVE-2020-13866 is an insecure permissions vulnerability that allows local users to escalate privileges.
5
Can CVE-2020-13866 be exploited remotely?
CVE-2020-13866 cannot be exploited remotely, as it requires local access to the system.