Privilege Escalation Vulnerability in Oculus Desktop by Facebook
CVE-2020-1885

7.8HIGH

Key Information:

Vendor

Facebook

Vendor
CVE Published:
8 April 2020

What is CVE-2020-1885?

A vulnerability exists in Oculus Desktop that allows an unprivileged user to write to arbitrary files by exploiting the OVRRedir.exe process. This flaw permits local users to elevate their privileges through methods that involve creating hard links to log files, potentially compromising system security.

Affected Version(s)

Oculus Desktop 1.44.0.328549

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-1885 : Privilege Escalation Vulnerability in Oculus Desktop by Facebook