PT-2020-20356 · Google · Google Earth Pro

CVE-2020-8895

·

Published

2020-04-21

·

Updated

2022-10-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Earth Pro versions prior to 7.3.3
Description The issue allows an attacker to execute unauthenticated remote code on the targeted system by inserting malicious local files, utilizing a technique known as DLL hijacking. This is made possible due to an Untrusted Search Path vulnerability in the Windows installer of the affected software.
Recommendations For Google Earth Pro versions prior to 7.3.3, update to version 7.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Windows installer to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8895

Affected Products

Google Earth Pro