Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-23T14:07:52
Updated: 2024-08-04T23:10:30.824Z
Reserved: 2019-05-17T00:00:00
Link: CVE-2019-12162
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-23T15:15:11.040
Modified: 2024-11-21T04:22:20.540
Link: CVE-2019-12162
Redhat
No data.