Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 10 min 132 bronnen 2 kritiek 4 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2020-37020

HIGH · 7.8 CVSS Gepubliceerd: CWE-428

Beschrijving

SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.

References