PT-2020-13946 · Hcl · Hcl Client Application Access
Published
2020-12-22
·
Updated
2021-07-21
·
CVE-2020-14231
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HCL Client Application Access version 9
Description
A vulnerability in the input parameter handling could potentially be exploited by an authenticated attacker, resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system, which would execute with the privileges of the currently logged in user.
Recommendations
For HCL Client Application Access version 9, consider restricting access to the input parameter handling functionality until a patch is available. As a temporary workaround, limit the privileges of the currently logged in user to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcl Client Application Access