Severity Rating: HIGH
Software Affected
•Windows installer for PostgreSQL versions12.3, 11.8, 10.13, 9.6.18, and
9.5.22
Overview
A vulnerability has been reported in PostgreSQL which could be exploited by
an attacker to execute arbitrary code on a targeted system.
Description
This vulnerability exists in PostgreSQL installer for Windows due to
failure to use fully-qualified paths for invoking system-provided
executables. An attacker could exploit this vulnerability by tricking a
user to install PostgreSQL from a directory that contains malicious files.
Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code with the privileges of the PostgreSQL installer on
the targeted system.
Note: - This vulnerability affects Windows installer only.
Solution
Apply appropriate updates as mentioned in:
Vendor Information
PostgreSQL.org
References
PostgreSQL.org
CybersecurityHelp
Vulmon
CVE Name
CVE-2020-10733