Vulnerability Description
CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cryptopro | Csp | < 5.0.0.10004 |
References
- https://www.youtube.com/watch?v=b5vPDmMtzwQExploitThird Party Advisory
- https://www.youtube.com/watch?v=b5vPDmMtzwQExploitThird Party Advisory
FAQ
What is CVE-2020-9331?
CVE-2020-9331 is a vulnerability with a CVSS score of 7.8 (HIGH). CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process cre...
How severe is CVE-2020-9331?
CVE-2020-9331 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9331?
Check the references section above for vendor advisories and patch information. Affected products include: Cryptopro Csp.