CVE-2020-18172

CRITICAL

Trezor Bridge <2.0.27 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0134
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
trezor/bridge 2.0.27
Published Jul 26, 2021
Tracked Since Feb 18, 2026