CVE-2020-7862
Estado: ModificadaAlta (8.8)—
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.11%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-20, CWE-120
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7862",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vuln@krcert.or.kr",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vuln@krcert.or.kr",
"affectedData": [
{
"vendor": "Helpu,inc",
"product": "HelpuViewer.exe",
"versions": [
{
"status": "affected",
"version": "2018.5.21.0",
"versionType": "custom",
"lessThanOrEqual": "2020.11.20.0"
}
],
"platforms": [
"x86, x64"
]
},
{
"vendor": "Helpu,inc",
"product": "HelpuServer.exe",
"versions": [
{
"status": "affected",
"version": "1.0.0.2",
"versionType": "custom",
"lessThanOrEqual": "2020.11.20.0"
}
],
"platforms": [
"x86, x64"
]
},
{
"vendor": "Helpu,inc",
"product": "HelpuFTClient.dll",
"versions": [
{
"status": "affected",
"version": "3.0.0.0 2020.11.20.0"
}
],
"platforms": [
"x86, x64"
]
},
{
"vendor": "Helpu,inc",
"product": "HelpuFTServer.dll",
"versions": [
{
"status": "affected",
"version": "3.0.0.0 2020.11.20.0"
}
],
"platforms": [
"x86, x64"
]
}
]
}
],
"published": "2021-06-24T11:15:07.740",
"references": [
{
"url": "https://helpu.co.kr/customer/download.html",
"tags": [
"Vendor Advisory"
],
"source": "vuln@krcert.or.kr"
},
{
"url": "https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094",
"tags": [
"Third Party Advisory"
],
"source": "vuln@krcert.or.kr"
},
{
"url": "https://helpu.co.kr/customer/download.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vuln@krcert.or.kr",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-120"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process."
},
{
"lang": "es",
"value": "Una vulnerabilidad solución de control remoto en el programa agente de HelpU, podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios. Esta vulnerabilidad es debido a un saneamiento insuficiente de la entrada cuando se comunica el proceso del cliente"
}
],
"lastModified": "2026-06-17T03:25:33.987",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:helpu:helpuftclient:3.0.0.0:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "D65D63E5-9478-4CB5-ABEC-58A6AB4D8241"
},
{
"criteria": "cpe:2.3:a:helpu:helpuftserver:3.0.0.0:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "51FCBC1B-E6C0-481A-AA65-4F6A14C5E5ED"
},
{
"criteria": "cpe:2.3:a:helpu:helpuserver:1.0.0.2:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "2F92BEDB-C1B4-4FD4-8540-A5090EF64F52"
},
{
"criteria": "cpe:2.3:a:helpu:helpuviewer:2018.5.21.0:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "6DA81C9C-27A9-4BA9-AECD-8BFDCA46C13D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vuln@krcert.or.kr"
}