CVE-2019-20456: Goverlan Client Agent
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.
Affected products
- Goverlan Client Agent: before 9.20.50 (fixed in 9.20.50)
- Goverlan Reach Console: before 9.50 (fixed in 9.50)
- Goverlan Reach Server: before 3.50 (fixed in 3.50)
Published 2020-02-16. Last modified 2026-06-17.