1E-2020-2001

Unquoted search path in 1E client

Bulletin ID
1E-2020-2001
Veröffentlicht am
29.12.2020
Letztes Update
21.11.2024
Schweregrad
Wichtig
CVSS
8.8 (High)
Zugewiesene CVE
CVE-2020-27645
Betroffene Produkte
1E Client for Windows

1. Vulnerability Details

CVE-ID

Description

The Inventory module of the 1E Client 5.0.0.745 doesn’t handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.

CVSS3.1 Score

Base Score 8.8 (High)

CVSS3.1 Vector String

Problem type

2. Affected products and versions

Product Versions

1E Client for Windows

5.0.x

Do you want to report a security issue?

TeamViewer’s security team will investigate every submission in our Vulnerability Disclosure Program.