Back to Labs
Security Advisory

CVE-2020-27645

About

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.

Weakness (CWE):CWE-428

Rainforest analyst review

The 1E Client references an executable via an unquoted path, so a local or authenticated user who can write to an intermediate directory can plant a binary that Windows executes with the service's elevated privileges. It's the well-worn unquoted-service-path escalation, requiring local write access at the right spot.

This is a post-compromise escalation primitive, not a way in. An attacker needs an existing foothold and the ability to write to a specific directory before the trick pays off, so it's the sort of thing used to climb from a limited account to a service account, not something scanned for across the internet.

We rank it below its 8.8 for remote-exposure purposes, because that score doesn't capture the local precondition. The useful checks are confirming the 1E Client version in the fleet and inspecting the ACLs on the directories along the unquoted path, since permissions are what actually make it exploitable.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2020-27645?

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.

How severe is CVE-2020-27645?

CVE-2020-27645 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.

How is CVE-2020-27645 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2020-27645?

Public advisories list the following as affected: client. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2020-27645?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email