Back to search
CVE-2020-26894
Published: Oct 8, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run the malicious "cmd.exe".
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://quality.livecode.com/show_bug.cgi?id=22942
x_refsource_MISC
https://github.com/livecode/livecode/pull/7454
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now