CVE-2020-36165
Veritas Desktop and Laptop Option vulnerability analysis and mitigation

Overview

An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. The vulnerability was discovered in December 2020 and assigned CVE-2020-36165 with a CVSS v3.1 Base Score of 9.3, indicating Critical severity. The issue affects DLO server and client installations across versions 9.3.3, 9.3.2, 9.3.1, 9.3, 9.2, 9.1, 9.0.1, and 9.0, with earlier unsupported versions potentially affected as well (Veritas Advisory).

Technical details

By default, on Windows systems, users can create directories under C:. A low privileged user can create a C:/ReleaseX64/ssl/openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. The vulnerability has been assigned a CVSS vector of AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating local access, low complexity, no privileges required, no user interaction needed, and high impact across confidentiality, integrity, and availability (Veritas Advisory).

Impact

This vulnerability gives the attacker administrator access on the system, allowing them to access all data and installed applications by default. The critical severity rating indicates the potential for complete system compromise through privilege escalation from a low-privileged user account to SYSTEM level access (Veritas Advisory).

Exploitability

The vulnerability can be exploited by any low-privileged user on the Windows system without requiring any privileges in DLO. The attack requires local access to the system but needs no special privileges or user interaction to execute, making it relatively straightforward to exploit (Veritas Advisory).

Mitigation and workarounds

For immediate mitigation without applying the patch, administrators can create the directory '\usr\local\ssl' under the root of all drives and set the ACL on the directory to deny write access to all other users. This prevents attackers from installing a malicious OpenSSL engine. For a permanent fix, customers under a current maintenance contract can download and install Veritas Desktop and Laptop Option version 9.5 (Veritas Advisory).

Additional resources


SourceThis report was generated using AI

Related Veritas Desktop and Laptop Option vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-36165HIGH8.8
  • Veritas Desktop and Laptop Option logoVeritas Desktop and Laptop Option
  • cpe:2.3:a:veritas:desktop_and_laptop_option
NoYesJan 06, 2021
CVE-2022-41319MEDIUM6.1
  • Veritas Desktop and Laptop Option logoVeritas Desktop and Laptop Option
  • cpe:2.3:a:veritas:desktop_and_laptop_option
NoYesSep 23, 2022
CVE-2020-36159MEDIUM5.3
  • Veritas Desktop and Laptop Option logoVeritas Desktop and Laptop Option
  • cpe:2.3:a:veritas:desktop_and_laptop_option
NoYesJan 05, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management