CVE-2020-25738: SQL Injection
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-25738.
What is the severity of CVE-2020-25738?
CVE-2020-25738 has a severity rating of medium (5.5).
What is the affected software?
The affected software is CyberArk Endpoint Privilege Manager (EPM) version 11.1.0.173.
How can attackers exploit CVE-2020-25738?
Attackers can exploit CVE-2020-25738 by injecting a DLL into a process that normally has credential access.
Are there any references for this vulnerability?
Yes, there are references available for this vulnerability. You can find them at the following links: [Reference 1](https://gist.github.com/inc0d3/47294c1e73ef8cbdc098e739d086efbc), [Reference 2](https://www.cyberark.com/resources/blog/introducing-cyberark-endpoint-privilege-manager)