CVE-2020-14418
30.01.2021, 06:15
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
| Vendor | Product | Version |
|---|---|---|
| cisco | advanced_malware_protection | 𝑥 < 7.2.13 |
| madshi | madcodehook | 𝑥 < 4.1.3 |
| morphisec | unified_threat_prevention_platform | 𝑥 < 3.5.9 |
| morphisec | unified_threat_prevention_platform | 4.0 ≤ 𝑥 < 4.1.2 |
𝑥
= Vulnerable software versions