PT-2020-20356 · Google · Google Earth Pro
Published
2020-04-21
·
Updated
2022-10-07
·
CVE-2020-8895
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Earth Pro versions prior to 7.3.3
Description
The issue allows an attacker to execute unauthenticated remote code on the targeted system by inserting malicious local files, utilizing a technique known as DLL hijacking. This is made possible due to an Untrusted Search Path vulnerability in the Windows installer of the affected software.
Recommendations
For Google Earth Pro versions prior to 7.3.3, update to version 7.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Windows installer to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Earth Pro