Описание
Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одновременно
EPSS
6.5 Medium
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with permissions to write to the file system could leverage this vulnerability to escalate privileges.
Уязвимость программного средства RoboHelp для публикации содержимого справки, политики и базы знаний, связанная с неконтролируемым элементом пути поиска. позволяющая нарушителю повысить свои привилегии
EPSS
6.5 Medium
CVSS3
9.3 Critical
CVSS2