← Back

CVE-2019-20456

nvd nist
Published: Feb 16, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

Affected (3)

3 products
Client Agent
Reach Console
Reach Server
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.20.50
Before 9.50
Before 3.50
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.