vendor:
inSync Windows Client
by:
Chris Lyne
7.8
CVSS
HIGH
Local Privilege Escalation
78
CWE
Product Name: inSync Windows Client
Affected Version From: 6.5.2002
Affected Version To: 6.5.2002
Patch Exists: NO
Related CWE: CVE-2019-3999
CPE: a:druva:insync:6.5.2
Platforms Tested: Windows
2020
Druva inSync Windows Client 6.5.2 – Local Privilege Escalation
Command injection in inSyncCPHwnet64 RPC service. Runs as nt authoritysystem, so we have a local privilege escalation.
Mitigation:
Apply the vendor-provided patch or upgrade to a newer version.