CVE-2020-14418

HIGH

Cisco Advanced Malware Protection < 7.2.13 - TOCTOU Race Condition

Title source: rule
STIX 2.1

Description

A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.

References (2)

Core 2

Scores

CVSS v3 7.0
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-367
Status published
Products (3)
cisco/advanced_malware_protection < 7.2.13
madshi/madcodehook < 4.1.3
morphisec/unified_threat_prevention_platform < 3.5.9
Published Jan 30, 2021
Tracked Since Feb 18, 2026