PT-2020-13372 · Teradici+1 · Teradici Pcoip Graphics Agent For Windows+2
Published
2020-05-28
·
Updated
2022-07-12
·
CVE-2020-13173
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Teradici PCoIP Standard Agent for Windows versions 19.11.1 and earlier
Teradici PCoIP Graphics Agent for Windows versions 19.11.1 and earlier
Description
The initialization of the
pcoip credential provider creates an insecure named pipe, allowing an attacker to intercept sensitive information or possibly elevate privileges by pre-installing an application that acquires the named pipe.Recommendations
For Teradici PCoIP Standard Agent for Windows versions 19.11.1 and earlier, consider updating to a version later than 19.11.1 to resolve the issue.
For Teradici PCoIP Graphics Agent for Windows versions 19.11.1 and earlier, consider updating to a version later than 19.11.1 to resolve the issue.
As a temporary workaround, consider restricting access to the
pcoip credential provider to minimize the risk of exploitation.Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teradici Pcoip Graphics Agent For Windows
Teradici Pcoip Standard Agent For Windows
Windows