Vulnerability Description
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teradici | Graphics Agent | < 20.04.1 |
| Teradici | Pcoip Standard Agent | < 20.04.1 |
Related Weaknesses (CWE)
References
- https://advisory.teradici.com/security-advisories/60/PatchVendor Advisory
- https://advisory.teradici.com/security-advisories/60/PatchVendor Advisory
FAQ
What is CVE-2020-13177?
CVE-2020-13177 is a vulnerability with a CVSS score of 7.8 (HIGH). The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which ...
How severe is CVE-2020-13177?
CVE-2020-13177 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13177?
Check the references section above for vendor advisories and patch information. Affected products include: Teradici Graphics Agent, Teradici Pcoip Standard Agent.