PT-2021-12690 · Zook · Zook
Published
2021-06-29
·
Updated
2021-07-02
·
CVE-2020-7869
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ZOOK software (affected versions not specified)
Description:
An improper input validation issue in the ZOOK software, a remote administration tool, could allow a remote attacker to create arbitrary files. The ZOOK viewer has a
Tight file CMD function that enables file creation. An attacker could exploit this to create and execute arbitrary files in the ZOOK agent program using Tight file CMD without proper authority.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zook