First published: Mon Mar 08 2021(Updated: )
Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drweb Security Space | =11.0 | |
Drweb Security Space | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23967 has a high severity rating due to its potential for privilege escalation to NT AUTHORITY\SYSTEM.
To mitigate CVE-2020-23967, users should update Dr.Web Security Space to the latest patched version.
CVE-2020-23967 affects local users of Dr.Web Security Space versions 11 and 12 without administrative privileges.
CVE-2020-23967 is caused by insufficient control during the autoupdate process in Dr.Web Security Space.
CVE-2020-23967 requires local access, meaning it cannot be exploited remotely without physical access to the affected system.