PT-2020-6095 · Microsoft+1 · Windows 7+2
Published
2020-08-28
·
Updated
2021-05-24
·
CVE-2020-24755
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ubiquiti UniFi Video version 3.10.13
Description
The issue is related to errors in the mechanism for checking the path of dynamically linked libraries in the UniFiVideo.exe executable file of Ubiquiti UniFi Video devices. Exploitation of this issue may allow an attacker to execute arbitrary code. The vulnerability was tested on Windows 7 x64 and Windows 10 x64 systems. When the executable starts, its first library validation is in the current directory, allowing for the impersonation and modification of the library to execute code on the system.
Recommendations
For version 3.10.13, consider restricting access to the library validation mechanism in the current directory until a patch is available. As a temporary workaround, avoid executing the UniFiVideo.exe file from untrusted directories to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifi Video
Windows 10
Windows 7