go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ServiSign Windows Versions - Remote Code Execution via LoadLibrary

TVN ID TVN-201910005
CVE ID CVE-2020-3925
CVSS 8.3 (High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products ServiSign Windows versions before version 1.0.19.0617
Description A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.
Solution Update to version >=1.0.19.1016 or contact tech support from CHANGING Inc.
Credit Weber Tsai (CHT Security)
Public Date 2020-02-03
Top