CVE-2020-9361: Medium severity cryptopro csp vulnerability
Published Oct 23, 2020
·Updated
CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.
Affected Software
1 affected component
CryptoPro CSP<=5.0.0.10004
Event History
Oct 23, 2020
CVE Published
via MITRE·04:48 AM
Data Sourced
via MITRE·04:48 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-9361?
CVE-2020-9361 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2020-9361?
To fix CVE-2020-9361, update CryptoPro CSP to version 5.0.0.10005 or later.
3
Who is affected by CVE-2020-9361?
Local users with the SeChangeNotifyPrivilege right on 64-bit platforms running affected versions of CryptoPro CSP are at risk.
4
What kind of vulnerability is CVE-2020-9361?
CVE-2020-9361 is a denial of service vulnerability stemming from mishandled user-mode input during process creation.
5
Can CVE-2020-9361 be exploited remotely?
No, CVE-2020-9361 requires local access to exploit the vulnerability.