A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18172
Reference (s):
- https://github.com/GitHubAssessments/CVE_07_2019/blob/master/Report.pdf