CVE-2020-7381

CVE-2020-7381

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.

Source: CVE-2020-7381

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다