LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run the malicious "cmd.exe".

Project Subscriptions

Vendors Products
Faulknermedia Subscribe
Wildlife Issues In The New Millennium Subscribe
Microsoft Subscribe
Windows Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-19424 LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run the malicious "cmd.exe".
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:03:22.843Z

Reserved: 2020-10-08T00:00:00.000Z

Link: CVE-2020-26894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-08T21:15:10.370

Modified: 2024-11-21T05:20:25.883

Link: CVE-2020-26894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses