vendor:
Druva inSync
by:
1F98D
7.8
CVSS
HIGH
Local Privilege Escalation
78
CWE
Product Name: Druva inSync
Affected Version From: 6.6.2003
Affected Version To: 6.6.2003
Patch Exists: NO
Related CWE: CVE-2020-5752
CPE: a:druva:insync:6.6.3
Platforms Tested: Windows
2020
Druva inSync Windows Client 6.6.3 – Local Privilege Escalation (PowerShell)
Druva inSync exposes an RPC service which is vulnerable to a command injection attack.
Mitigation:
Apply the vendor-provided patch or update to the latest version of Druva inSync.