CVE-2020-24755

In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).
References
Link Resource
https://www.youtube.com/watch?v=T41h4yeh9dk Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:unifi_video:3.10.13:*:*:*:*:*:*:*

Information

Published : 2021-05-17 15:15

Updated : 2021-05-24 10:48


NVD link : CVE-2020-24755

Mitre link : CVE-2020-24755


JSON object : View

CWE
CWE-427

Uncontrolled Search Path Element

Advertisement

dedicated server usa

Products Affected

ui

  • unifi_video