VYPR
Medium severity5.5NVD Advisory· Published Oct 23, 2020· Updated Jun 17, 2026

CVE-2020-9361

CVE-2020-9361

Description

CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.

Affected products

3
  • CryptoPro/CSP3 versions
    cpe:2.3:a:cryptopro:csp:*:*:*:*:*:*:x64:*+ 2 more
    • cpe:2.3:a:cryptopro:csp:*:*:*:*:*:*:x64:*range: <=5.0.0.10004
    • (no CPE)
    • (no CPE)range: <=5.0.0.10004

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.