CVE-2020-25502: High severity Cybereason Endpoint Detection And Response vulnerability
Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25502?
CVE-2020-25502 has a high severity rating due to its potential to allow local attackers to execute code with elevated privileges.
How do I fix CVE-2020-25502?
To fix CVE-2020-25502, upgrade to Cybereason EDR version 20.2.1 or later, as this version mitigates the DLL hijacking vulnerability.
What versions of Cybereason are affected by CVE-2020-25502?
CVE-2020-25502 affects Cybereason EDR versions prior to 20.2.1, including 19.1.282, versions between 19.2.0 and 19.2.182, versions between 20.1.0 and 20.1.343, and version 20.2.0.
Can CVE-2020-25502 be exploited remotely?
CVE-2020-25502 cannot be exploited remotely as it requires local access to the affected system.
What impact does CVE-2020-25502 have on my system?
CVE-2020-25502 allows an attacker with local access to run unauthorized code with elevated rights, potentially compromising system integrity.