Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3811 | Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:10:30.824Z
Reserved: 2019-05-17T00:00:00
Link: CVE-2019-12162
No data.
Status : Modified
Published: 2019-07-23T15:15:11.040
Modified: 2024-11-21T04:22:20.540
Link: CVE-2019-12162
No data.
OpenCVE Enrichment
No data.
EUVD