ZeroHour

CVE-2019-20456

CVSS 3.1
7.8 high
EPSS
<1%p52
Published
()
Modified
Description

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

Vendors
goverlan
Products
client agent, reach console, reach server
Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.