CVE-2020-5752
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 8.6%
from disclosure to weapon1 days
Published on NVDMay 21
1st PoC+1d
metasploitFeb 25
exploitation probability
8.6%top 5% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
Affected products
n/a · Druva inSync Windows Clientpublic PoCs found — 6✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/48505exploitdbwww.exploit-db.com/exploits/49211unverifiedgithubgithub.com/yevh/CVE-2020-5752-Druva-inSync-Windows-Client-6.6.3---Local-Privilege-Escalation-PowerShell-★ 4githubgithub.com/x0rbeexd/CVE-2020-5752★ 1cve_referencepacketstormsecurity.com/files/157802/Druva-inSync-Windows-Client-6.6.3-Local-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/160404/Druva-inSync-Windows-Client-6.6.3-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.