PT-2020-20356 · Google · Google Earth Pro

Published

2020-04-21

·

Updated

2022-10-07

·

CVE-2020-8895

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Earth Pro versions prior to 7.3.3
Description The issue allows an attacker to execute unauthenticated remote code on the targeted system by inserting malicious local files, utilizing a technique known as DLL hijacking. This is made possible due to an Untrusted Search Path vulnerability in the Windows installer of the affected software.
Recommendations For Google Earth Pro versions prior to 7.3.3, update to version 7.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Windows installer to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2020-8895

Affected Products

Google Earth Pro