CVE-2020-8884

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*
cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:windows:*:*

Information

Published : 2021-01-06 06:15

Updated : 2021-01-13 11:21


NVD link : CVE-2020-8884

Mitre link : CVE-2020-8884


JSON object : View

CWE
CWE-502

Deserialization of Untrusted Data

Advertisement

dedicated server usa

Products Affected

proofpoint

  • insider_threat_management