Code Execution Vulnerability in Veritas DLO Products
CVE-2020-36165
What is CVE-2020-36165?
A vulnerability in Veritas Desktop and Laptop Option (DLO) prior to version 9.4 allows a low privileged user to exploit the OpenSSL library loading mechanism. Upon service startup, the software attempts to load the OpenSSL configuration file from a specified directory, which is absent by default. By creating this missing configuration file in the accessible directory, a malicious user can redirect the loading process to a rogue OpenSSL engine. This action can result in arbitrary code execution with SYSTEM privileges, posing significant risks, including complete access to sensitive data and installed applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
