CVE-2020-10733
Last modified
CVE-2020-10733 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 9.5, < 9.5.22 |
| Postgresql | Postgresql | >= 9.6, < 9.6.18 |
| Postgresql | Postgresql | >= 10.0, < 10.13 |
| Postgresql | Postgresql | >= 11.0, < 11.8 |
| Postgresql | Postgresql | >= 12.0, < 12.3 |
References
- https://security.netapp.com/advisory/ntap-20201001-0006/Third Party Advisory
- https://www.postgresql.org/about/news/2038/Vendor Advisory
- https://www.postgresql.org/support/security/11/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20201001-0006/Third Party Advisory
- https://www.postgresql.org/about/news/2038/Vendor Advisory
- https://www.postgresql.org/support/security/11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10733?
How severe is CVE-2020-10733?
How do I fix CVE-2020-10733?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10728A flaw was found in automationbroker/apb container in versio…7.8
- CVE-2020-10729A flaw was found in the use of insufficiently random values …5.5
- CVE-2020-1073A remote code execution vulnerability exists in the way that…8.1
- CVE-2020-10730A NULL pointer dereference, or possible use-after-free flaw …6.5
- CVE-2020-10731A flaw was found in the nova_libvirt container provided by t…9.9
- CVE-2020-10732A flaw was found in the Linux kernel's implementation of Use…4.4
- CVE-2020-10734A vulnerability was found in keycloak in the way that the OI…3.3
- CVE-2020-10735A flaw was found in python. In algorithms with quadratic tim…7.5
- CVE-2020-10736An authorization bypass vulnerability was found in Ceph vers…8
- CVE-2020-10737A race condition was found in the mkhomedir tool shipped wit…6.3
- CVE-2020-10738A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 be…8.8
- CVE-2020-10739Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contai…7.5
Are you affected by CVE-2020-10733?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
