Files
CVEs-PoC/2020/CVE-2020-13533.md
T
2024-05-25 21:48:12 +02:00

18 lines
870 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
### [CVE-2020-13533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13533)
![](https://img.shields.io/static/v1?label=Product&message=Dream%20Report&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-276%3A%20Incorrect%20Default%20Permissions&color=brighgreen)
### Description
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively backdoor the installation files and escalate privileges when a new user logs in and uses the application.
### POC
#### Reference
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1146
#### Github
No PoCs found on GitHub currently.