TVN ID | TVN-202012002 |
---|---|
CVE ID | CVE-2020-25843 |
CVSS | 8.1 (High) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Affected Products | CHANGING Inc. NHIServiSignAdapter for Windows 1.0.20.0218 |
Description | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. |
Solution | Update to version 1.0.20.1109 |
Credit | Angelboy (DEVCORE https://devco.re) |
Public Date | 2020-12-31 |