Untrusted search path in PostgreSQL - CVE-2020-10733
Published: May 14, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on he system.
The vulnerability exists due to Windows installer runs executables from uncontrolled directories. A local user can trick the victim to install PostgreSQL from a directory that contains a malicious files and execute arbitrary code on the system with elevated privileges.
Note, this vulnerability affects Windows installer only.
Affected software
Zoho ManageEngine OpManager
Dell Security Management Server
How to mitigate CVE-2020-10733
Zoho ManageEngine OpManager - addressed in versions 12.5 125127, 12.5 125397
Dell Security Management Server - update to 11.0.1