CVE-2020-5752 describes a relative path traversal vulnerability in Druva inSync Windows Client version 6.6.3. This flaw allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. With a CVSS score of 7.8 (High), exploitation is straightforward, requiring only local access and low privileges, leading to complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog, public exploit modules exist for Metasploit and ExploitDB, indicating readily available attack tools, despite a lack of significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.6.3CPE matchmatch criteria | cpe:2.3:a:druva:insync_client:6.6.3:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020Druva inSync Windows Client Local Privilege Escalation (CVE-2019-3999 Patch Bypass)
May 21, 2020