First published: Sun Jun 07 2020(Updated: )
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Advanced Monitoring Agent | <10.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13912 has been classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2020-13912, upgrade the SolarWinds Advanced Monitoring Agent to version 10.8.9 or later.
CVE-2020-13912 can be exploited via a local privilege escalation attack using a malicious .exe file.
Local users of SolarWinds Advanced Monitoring Agent versions prior to 10.8.9 are affected by CVE-2020-13912.
No, CVE-2020-13912 requires local access to the affected system to exploit.