PT-2021-9618 · Syncfusion · Syncfusion Dashboard Service

Yuri Kramarz

·

Published

2021-04-09

·

Updated

2022-07-30

·

CVE-2020-13532

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dream Report version 5 R20-2
Description A privilege escalation issue exists, allowing attackers to replace the Syncfusion Dashboard Service service binary and escalate privileges to NT SYSTEM. This can be triggered by providing a malicious file.
Recommendations For Dream Report version 5 R20-2, consider restricting access to the Syncfusion Dashboard Service to minimize the risk of exploitation. Additionally, monitor the service binary for any unauthorized changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13532

Affected Products

Syncfusion Dashboard Service