#VU52013 Incorrect default permissions in Dream Report - CVE-2020-13533
Published: April 9, 2021
Dream Report
Ocean Data Systems
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the application in the "ods_rtm_launch" and "ods_usc" Run Keys. A remote attacker can use a specially crafted file and gain elevated privileges on the target system.