CVE-2020-23967

HIGH

Dr.Web Security Space <12 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://amonitoring.ru/article/drweb/
Exploit, Third Party Advisory x_refsource_misc
https://habr.com/ru/company/pm/blog/509592/
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=q7Kqi7kE59U

Scores

CVSS v3 7.8
EPSS 0.0032
EPSS Percentile 23.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (2)
drweb/security_space 11.0
drweb/security_space 12.0
Published Mar 08, 2021
Tracked Since Feb 18, 2026