PT-2020-16307 · Dual Dhcp Dns · Dual Dhcp Dns Server

Published

2020-10-28

·

Updated

2023-02-27

·

CVE-2020-26133

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dual DHCP DNS Server version 7.40
Description An issue was discovered due to insufficient access restrictions in the default installation directory, allowing an attacker to elevate privileges by replacing the DualServer.exe binary.
Recommendations For Dual DHCP DNS Server version 7.40, consider restricting access to the default installation directory to prevent unauthorized replacement of the DualServer.exe binary. As a temporary workaround, monitor the integrity of the DualServer.exe binary to detect any potential tampering. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2020-26133

Affected Products

Dual Dhcp Dns Server