CVE-2020-14418: High severity cisco advanced malware protection for endpoints vulnerability
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14418?
CVE-2020-14418 is a TOCTOU vulnerability in madCodeHook that allows local attackers to elevate their privileges to SYSTEM.
How can the TOCTOU vulnerability be exploited?
The TOCTOU vulnerability in madCodeHook can be exploited through path redirection via directory junctions.
Which software versions are affected by CVE-2020-14418?
The affected software versions include Cisco Advanced Malware Protection up to version 7.2.13, Madshi Madcodehook up to version 4.1.3, and Morphisec Unified Threat Prevention Platform up to version 3.5.9 or version 4.0 to 4.1.2.
What is the severity of CVE-2020-14418?
CVE-2020-14418 has a severity level of high (7).
How can I fix the TOCTOU vulnerability in madCodeHook?
There is currently no fix available for the TOCTOU vulnerability in madCodeHook. It is recommended to update to the latest version when a fix becomes available.