PT-2020-6095 · Microsoft+1 · Windows 7+2

Published

2020-08-28

·

Updated

2021-05-24

·

CVE-2020-24755

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ubiquiti UniFi Video version 3.10.13
Description The issue is related to errors in the mechanism for checking the path of dynamically linked libraries in the UniFiVideo.exe executable file of Ubiquiti UniFi Video devices. Exploitation of this issue may allow an attacker to execute arbitrary code. The vulnerability was tested on Windows 7 x64 and Windows 10 x64 systems. When the executable starts, its first library validation is in the current directory, allowing for the impersonation and modification of the library to execute code on the system.
Recommendations For version 3.10.13, consider restricting access to the library validation mechanism in the current directory until a patch is available. As a temporary workaround, avoid executing the UniFiVideo.exe file from untrusted directories to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03002
CVE-2020-24755

Affected Products

Unifi Video
Windows 10
Windows 7