CVE-2020-13542

HIGH

LogicalDoc 8.5.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or replace DLL files loaded by the service, both which get executed by a service thus executing arbitrary commands with System privileges.

References (1)

Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1154

Scores

CVSS v3 7.8
EPSS 0.0060
EPSS Percentile 44.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
logicaldoc/logicaldoc 8.5.1
Published Dec 03, 2020
Tracked Since Feb 18, 2026