Vulnerability Description
CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cryptopro | Csp | <= 5.0.0.10004 |
References
- https://www.youtube.com/watch?v=b5vPDmMtzwQExploitThird Party Advisory
- https://www.youtube.com/watch?v=b5vPDmMtzwQExploitThird Party Advisory
FAQ
What is CVE-2020-9361?
CVE-2020-9361 is a vulnerability with a CVSS score of 5.5 (MEDIUM). CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation...
How severe is CVE-2020-9361?
CVE-2020-9361 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9361?
Check the references section above for vendor advisories and patch information. Affected products include: Cryptopro Csp.