PT-2020-16306 · Home · Home Dns Server
Oceloot
·
Published
2020-10-28
·
Updated
2023-02-27
·
CVE-2020-26132
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Home DNS Server version 0.10
Description
An issue was discovered due to insufficient access restrictions in the default installation directory, allowing an attacker to elevate privileges by replacing the HomeDNSServer.exe binary.
Recommendations
For Home DNS Server version 0.10, consider restricting access to the default installation directory to prevent unauthorized replacement of the HomeDNSServer.exe binary. As a temporary workaround, monitor the directory for any changes to the binary and restrict execution of the binary to trusted users until a fix is available.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Dns Server