PT-2020-16742 · 1E · 1E Client

Published

2020-12-29

·

Updated

2021-07-21

·

CVE-2020-27643

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions 1E Client versions 4.1.0.267 through 5.0.0.745
Description The issue allows remote authenticated users and local users to create and modify files in protected directories, leading to partial privilege escalation. This is achieved by creating a junction point to a system directory. Additionally, the Inventory module of the 1E Client does not handle an unquoted path when executing a specific executable, potentially allowing remote authenticated users and local users to gain elevated privileges by placing a malicious file in a specific temporary directory.
Recommendations For 1E Client version 4.1.0.267, update to a version that fixes the issue. For 1E Client version 5.0.0.745, update to a version that fixes the issue. As a temporary workaround, consider restricting access to the Tachyon.Performance.Metrics.exe executable and the %PROGRAMDATA%1EClient directory to minimize the risk of exploitation. Avoid using unquoted paths when executing system executables until the issue is resolved.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27643

Affected Products

1E Client