CVE-2020-9858
HIGHApple Windows Migration Assistant < 2.2.0.0 - Uncontrolled Search Path
Title source: ruleDescription
A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.
References (1)
Scores
CVSS v3
7.8
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
apple/windows_migration_assistant
< 2.2.0.0
Timeline
Published
Jun 09, 2020
Tracked Since
Feb 18, 2026