mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 03:41:53 +02:00
18 lines
863 B
Markdown
18 lines
863 B
Markdown
### [CVE-2020-8240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8240)
|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|