CVE-2020-23060: Buffer Overflow
Published Oct 22, 2021
·Updated
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.
Affected Software
1 affected component
Tonec Internet Download Manager=6.37.11.1
Event History
Oct 22, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23060?
CVE-2020-23060 is classified as a critical vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2020-23060?
To remediate CVE-2020-23060, users should update Internet Download Manager to the latest version available.
3
What types of attacks can CVE-2020-23060 enable?
CVE-2020-23060 allows attackers to execute local process privilege escalation via a carefully crafted ef2 file.
4
Which software versions are affected by CVE-2020-23060?
CVE-2020-23060 affects Internet Download Manager version 6.37.11.1.
5
Is CVE-2020-23060 a remote or local vulnerability?
CVE-2020-23060 is a local vulnerability that requires access to the affected system to exploit.