Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13770

Опубликовано: 12 нояб. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
Версия до 2020.1.1 (включая)

EPSS

Процентиль: 29%
0.00105
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-276

Связанные уязвимости

github
больше 3 лет назад

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

EPSS

Процентиль: 29%
0.00105
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-276