PT-2020-10603 · Unknown · Autoupdater.Net

Ray Doyle

·

Published

2020-03-23

·

Updated

2023-02-03

·

CVE-2019-20627

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AutoUpdater.NET versions prior to 1.5.8
Description The issue affects AutoUpdater.NET and is related to an XXE (XML External Entity) vulnerability in the AutoUpdater.cs file. This allows for potential exploitation.
Recommendations For versions prior to 1.5.8, update to version 1.5.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the AutoUpdater.cs file until a patch is applied.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20627
GHSA-75P2-HGW4-G7F7

Affected Products

Autoupdater.Net