CVE-2019-20456

HIGH

Goverlan Reach Console <9.50/Server <3.50/Client Agent <9.20.50 - Local Privilege Escalation via DLL Hijacking

Title source: llm
STIX 2.1

Description

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0072
EPSS Percentile 49.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (3)
goverlan/client_agent < 9.20.50
goverlan/reach_console < 9.50
goverlan/reach_server < 3.50
Published Feb 16, 2020
Tracked Since Feb 18, 2026