Unrated severityNVD Advisory· Published Aug 4, 2020· Updated Aug 4, 2024
CVE-2020-6012
CVE-2020-6012
Description
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.
Affected products
1- Range: before 1.0.713
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- danishcyberdefence.dk/blog/zonealarm-check-pointmitrex_refsource_MISC
- www.zonealarm.com/anti-ransomware/release-historymitrex_refsource_MISC
- www.zonealarm.com/software/extreme-security/release-historymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.