CVE-2019-12162 Information
Feb 14, 2021
cve
Description
Upwork Time Tracker 5.2.2.716 doesn’t verify the SHA256 hash of the downloaded program update before running it which could lead to code execution or local privilege escalation by replacing the original update.exe.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://support.upwork.com/hc/en-us/categories/360001180954 https://vuldb.com/?id.138406
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: