PT-2021-12690 · Zook · Zook

Published

2021-06-29

·

Updated

2021-07-02

·

CVE-2020-7869

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ZOOK software (affected versions not specified)
Description: An improper input validation issue in the ZOOK software, a remote administration tool, could allow a remote attacker to create arbitrary files. The ZOOK viewer has a Tight file CMD function that enables file creation. An attacker could exploit this to create and execute arbitrary files in the ZOOK agent program using Tight file CMD without proper authority.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7869

Affected Products

Zook