Vulnerability Description
Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in a location that other unprivileged users have access to.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Z-Cron | Z-Cron | 5.6 |
Related Weaknesses (CWE)
References
- https://blog.spookysec.net/zcron/ExploitThird Party Advisory
- https://blog.spookysec.net/zcron/ExploitThird Party Advisory
FAQ
What is CVE-2020-11799?
CVE-2020-11799 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in ...
How severe is CVE-2020-11799?
CVE-2020-11799 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11799?
Check the references section above for vendor advisories and patch information. Affected products include: Z-Cron Z-Cron.