PT-2021-11945 · Veritas · Veritas Desktop/Laptop Option

Published

2021-01-06

·

Updated

2021-01-12

·

CVE-2020-36165

CVSS v3.1

9.3

Critical

VectorAC:L/AV:L/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: Veritas Desktop and Laptop Option (DLO) versions prior to 9.4
Description: An issue in Veritas Desktop and Laptop Option (DLO) allows a low-privileged user to create a malicious configuration file that can load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker to access all data and installed applications. The issue impacts both DLO server and client installations.
Recommendations: For versions prior to 9.4, update to version 9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:/ReleaseX64/ssl directory to prevent low-privileged users from creating a malicious openssl.cnf configuration file.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-36165

Affected Products

Veritas Desktop/Laptop Option