Vulnerability Description
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 1E | Client | 4.1.0.267 |
Related Weaknesses (CWE)
References
- https://help.1e.com/display/GI/1E+Security+Advisory-1E+Client+for+Windows%3A+CVEVendor Advisory
- https://help.1e.com/display/GI/1E+Security+Advisory-1E+Client+for+Windows%3A+CVEVendor Advisory
FAQ
What is CVE-2020-27643?
CVE-2020-27643 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not n...
How severe is CVE-2020-27643?
CVE-2020-27643 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27643?
Check the references section above for vendor advisories and patch information. Affected products include: 1E Client.