First published: Wed Apr 08 2020(Updated: )
Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oculus Desktop | <1.44.0.32849 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1885 is a vulnerability that allows local users to write to arbitrary files and gain privileges in Oculus Desktop before version 1.44.0.32849 on Windows.
CVE-2020-1885 has a severity rating of 7.8, which is considered high.
Oculus Desktop versions up to but excluding 1.44.0.32849 on Windows are affected by CVE-2020-1885.
Local users can exploit CVE-2020-1885 by leveraging a hard link to a log file to write to an unprivileged file from the privileged OVRRedir.exe process in Oculus Desktop.
To fix CVE-2020-1885, users should update Oculus Desktop to version 1.44.0.32849 or later.