PT-2020-14933 · Ghisler · Total Commander

Published

2020-10-21

·

Updated

2023-03-15

·

CVE-2020-17381

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghisler Total Commander version 9.51
Description An issue was discovered due to insufficient access restrictions in the default installation directory, allowing an attacker to elevate privileges by replacing the %SYSTEMDRIVE%totalcmdTOTALCMD64.EXE binary.
Recommendations For Ghisler Total Commander version 9.51, consider restricting access to the installation directory to prevent unauthorized modifications to the TOTALCMD64.EXE binary until a patch is available.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2020-17381

Affected Products

Total Commander