VulnerabilityModified
CVE-2019-12162
Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
HIGH 7.8EPSS 0.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-494
- Affected
- upwork/time tracker
- Source
- cve@mitre.org
References
- https://support.upwork.com/hc/en-us/categories/360001180954Product, Vendor Advisory
- https://vuldb.com/?id.138406Third Party Advisory
- https://support.upwork.com/hc/en-us/categories/360001180954Product, Vendor Advisory
- https://vuldb.com/?id.138406Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.