Untrusted search path in kerberos - CVE-2020-13110
Published: May 12, 2020 / Updated: May 18, 2020
kerberos
Faisal Salman
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLLs without specifying a full path. This may allow a local user to create a
file with the same name in a folder that precedes the intended file in
the DLL path search and execute arbitrary code on the system with elevated privileges.