An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the %SYSTEMDRIVE%totalcmdTOTALCMD64.EXE binary.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17381
Reference (s):
- https://github.com/an0ry/advisories/blob/main/CVE-2020-17381.md

