VDB

GCVE-110-CERTCC-2020-208577

GCVE-110-CERTCC-2020-208577
Advisory Published
Vulnetix · Advisory published October 20, 2020
### Overview Chocolatey Boxstarter fails to properly set ACLs, which can allow an unprivileged Windows user to be able to run arbitrary code with SYSTEM privileges. ### Description **CVE-2020-15264** The Chocolatey Boxstarter installer fails to set a secure access-control list (ACL) on the `C:\ProgramData\Boxstarter` directory, which is added to the system-wide PATH environment variable. A privilege escalation vulnerability is introduced since any location in the system-wide PATH environment variable may be used to load code that runs with privileges. ### Impact By placing a specially-crafted DLL file in the `C:\ProgramData\Boxstarter` directory, an unprivileged user may be able to execute arbitrary code with SYSTEM privileges on a Windows system with the vulnerable Boxstarter software installed. See [DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1574/001/) for more details. ### Solution ####Apply an update This vulnerability is addressed in Chocolatey Boxstarter version 2.13.0. Please see the [security advisory](https://github.com/chocolatey/boxstarter/security/advisories/GHSA-rpgx-h675-r3jf) for more details. ### Acknowledgements This vulnerability was reported by Will Dormann of the CERT/CC. This document was written by Will Dormann.

Browse GCVE Records

74,352 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›