SB2020111081 - Privilege escalation in LogicalDoc
Published: November 10, 2020 Updated: November 23, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect default permissions (CVE-ID: CVE-2020-13542)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions in the file system permissions of LogicalDoc installation. A local attacker can either replace the service binary or replace DLL files loaded by the service, view contents of files and directories or modify them.
Remediation
Install update from vendor's website.