CVE-2020-9858

HIGH

Apple Windows Migration Assistant < 2.2.0.0 - Uncontrolled Search Path

Title source: rule

Description

A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

apple/windows_migration_assistant < 2.2.0.0

Timeline

Published Jun 09, 2020
Tracked Since Feb 18, 2026