Vulnerability Description
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges by placing a malicious cryptbase.dll file in %WINDIR%\Temp\.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 1E | Client | 5.0.0.745 |
Related Weaknesses (CWE)
References
- https://help.1e.com/display/GI/1E+Security+Advisory-1E+Client+for+Windows%3A+CVEVendor Advisory
- https://help.1e.com/display/GI/1E+Security+Advisory-1E+Client+for+Windows%3A+CVEVendor Advisory
FAQ
What is CVE-2020-27644?
CVE-2020-27644 is a vulnerability with a CVSS score of 8.8 (HIGH). The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and l...
How severe is CVE-2020-27644?
CVE-2020-27644 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27644?
Check the references section above for vendor advisories and patch information. Affected products include: 1E Client.