PT-2020-16306 · Home · Home Dns Server

Oceloot

·

Published

2020-10-28

·

Updated

2023-02-27

·

CVE-2020-26132

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Home DNS Server version 0.10
Description An issue was discovered due to insufficient access restrictions in the default installation directory, allowing an attacker to elevate privileges by replacing the HomeDNSServer.exe binary.
Recommendations For Home DNS Server version 0.10, consider restricting access to the default installation directory to prevent unauthorized replacement of the HomeDNSServer.exe binary. As a temporary workaround, monitor the directory for any changes to the binary and restrict execution of the binary to trusted users until a fix is available.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2020-26132

Affected Products

Home Dns Server