Arbitrary Code Execution in PostgreSQL Installer by PostgreSQL
CVE-2020-10733
7.3HIGH
Summary
The PostgreSQL installer for versions 9.5 through 12 has a vulnerability that allows an attacker, with proper permissions, to place malicious executables in directories searched by the installer. Due to the lack of fully-qualified paths when invoking system-provided executables, this allows those malicious executables to take precedence, potentially leading to execution of arbitrary code with administrative privileges during the installation process.
Affected Version(s)
PostgreSQL 9.5, 9.6, 10, 11, 12
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved