Aller au contenu

Fiche vulnérabilité

CVE-2020-9331 : faille élevée cryptopro csp (CVSS 7.8)

Description

CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
23 oct. 2020
Dernière mise à jour
17 juin 2026

Produits concernés

  • cryptopro csp

Références

Rechercher une autre vulnérabilité dans la base CVE