PT-2021-11945 · Veritas · Veritas Desktop/Laptop Option
Published
2021-01-06
·
Updated
2021-01-12
·
CVE-2020-36165
CVSS v3.1
9.3
Critical
| Vector | AC:L/AV:L/A:H/C:H/I:H/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions:
Veritas Desktop and Laptop Option (DLO) versions prior to 9.4
Description:
An issue in Veritas Desktop and Laptop Option (DLO) allows a low-privileged user to create a malicious configuration file that can load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker to access all data and installed applications. The issue impacts both DLO server and client installations.
Recommendations:
For versions prior to 9.4, update to version 9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:/ReleaseX64/ssl directory to prevent low-privileged users from creating a malicious openssl.cnf configuration file.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas Desktop/Laptop Option