CVE-2020-36161: High severity veritas aptare it analytics vulnerability
An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a directory at the configuration file locations. When the Windows system restarts, a malicious OpenSSL engine could exploit arbitrary code execution as SYSTEM. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-36161.
What is the severity of CVE-2020-36161?
The severity of CVE-2020-36161 is high, with a severity value of 8.8.
What is the affected software for CVE-2020-36161?
The affected software for CVE-2020-36161 is Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3.
How can a low privileged user exploit CVE-2020-36161?
A low privileged user can exploit CVE-2020-36161 by creating a directory at the configuration file locations on Windows systems.
Is there a patch available for CVE-2020-36161?
Yes, patches are available for Veritas APTARE 10.4 and 10.5 to fix CVE-2020-36161. Users should update to the latest patch version.