CVE-2020-15264
Last modified
CVE-2020-15264 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a privileged service is looking for. For example, WptsExtensions.dll When Windows starts, it'll execute the code in DllMain() with SYSTEM privileges. Any unprivileged user can execute code with SYSTEM privileges. The issue is fixed in version 3.13.0
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chocolatey | Boxstarter | < 2.13.0 |
References
- https://github.com/chocolatey/boxstarter/commit/67e320491813550b48900e87105a34ceefdcf633Patch, Third Party Advisory
- https://github.com/chocolatey/boxstarter/security/advisories/GHSA-rpgx-h675-r3jfThird Party Advisory
- https://www.kb.cert.org/vuls/id/208577Third Party Advisory
- https://github.com/chocolatey/boxstarter/commit/67e320491813550b48900e87105a34ceefdcf633Patch, Third Party Advisory
- https://github.com/chocolatey/boxstarter/security/advisories/GHSA-rpgx-h675-r3jfThird Party Advisory
- https://www.kb.cert.org/vuls/id/208577Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15264?
How severe is CVE-2020-15264?
How do I fix CVE-2020-15264?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15259ad-ldap-connector's admin panel before version 5.0.13 does n…8.8
- CVE-2020-1526An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-15260PJSIP is a free and open source multimedia communication lib…6.8
- CVE-2020-15261On Windows the Veyon Service before version 4.4.2 contains a…6.7
- CVE-2020-15262In webpack-subresource-integrity before version 1.5.1, all d…3.7
- CVE-2020-15263In platform before version 9.4.4, inline attributes are not …6.1
- CVE-2020-15265In Tensorflow before version 2.4.0, an attacker can pass an …7.5
- CVE-2020-15266In Tensorflow before version 2.4.0, when the `boxes` argumen…7.5
- CVE-2020-15269In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired u…9.1
- CVE-2020-1527An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-15270Parse Server (npm package parse-server) broadcasts events to…4.3
- CVE-2020-15271In lookatme (python/pypi package) versions prior to 2.3.0, t…8.8
Are you affected by CVE-2020-15264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
