go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

CHANGING Inc. NHIServiSignAdapter Windows Versions - Arbitrary File Access

TVN ID TVN-202012001
CVE ID CVE-2020-25842
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products CHANGING Inc. NHIServiSignAdapter for Windows 1.0.20.0218
Description The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
Solution Update to version 1.0.20.1109
Credit Angelboy (DEVCORE https://devco.re)
Public Date 2020-12-31
Top