Files
CVEs-PoC/2020/CVE-2020-10138.md
T
2024-05-25 21:48:12 +02:00

21 lines
1.2 KiB
Markdown

### [CVE-2020-10138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10138)
![](https://img.shields.io/static/v1?label=Product&message=Cyber%20Backup&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cyber%20Protect&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=12.5%3C%2016363%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=15%3C%2024600%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-284%20Improper%20Access%20Control&color=brighgreen)
### Description
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/chnzzh/OpenSSL-CVE-lib