HIGH 7.3 Microsoft
CVE-2020-0570
Uncontrolled search path in the QT Library before 5.14.0 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
Microsoft Security Update 2020-Sep: Uncontrolled search path in the QT Library before 5.14.0 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
Affected Products
- cm1 qt5-qtbase 5.12.11-2 on CBL Mariner 1.0
- cbl2 qt5-qtsvg 5.12.11-3 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0570
- https://nvd.nist.gov/vuln/detail/CVE-2020-0570
This high severity vulnerability with a CVSS score of 7.3 was published on 2020-09-08 via Microsoft. Affected: cm1 qt5-qtbase 5.12.11-2 on CBL Mariner 1.0, cbl2 qt5-qtsvg 5.12.11-3 on CBL Mariner 2.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.