Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
References
Link | Resource |
---|---|
https://support.upwork.com/hc/en-us/categories/360001180954 | Product Vendor Advisory |
https://vuldb.com/?id.138406 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-23T14:07:52
Updated: 2019-07-23T14:07:52
Reserved: 2019-05-17T00:00:00
Link: CVE-2019-12162
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-07-23T15:15:11.040
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-12162
JSON object: View
Redhat Information
No data.
CWE