Files
CVEs-PoC/2020/CVE-2020-25045.md
T
2024-05-25 21:48:12 +02:00

18 lines
832 B
Markdown

### [CVE-2020-25045](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25045)
![](https://img.shields.io/static/v1?label=Product&message=Kaspersky%20Security%20Center%20%26%20Kaspersky%20Security%20Center%20Web%20Console&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Local%20Privilege%20Escalation%20(LPE)&color=brighgreen)
### Description
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
### POC
#### Reference
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#290720
#### Github
- https://github.com/404notf0und/CVE-Flow