Lucene search

K
cveFacebookCVE-2020-1885
HistoryApr 08, 2020 - 8:15 p.m.

CVE-2020-1885

2020-04-0820:15:14
CWE-59
facebook
web.nvd.nist.gov
22
cve-2020-1885
security vulnerability
ovrredir.exe
oculus desktop
windows
local privilege escalation
file write vulnerability

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.1%

Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file.

Affected configurations

Nvd
Node
oculusdesktopRange<1.44.0.32849windows
VendorProductVersionCPE
oculusdesktop*cpe:2.3:a:oculus:desktop:*:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "product": "Oculus Desktop",
    "vendor": "Facebook",
    "versions": [
      {
        "status": "affected",
        "version": "1.44.0.328549"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2020-1885