CVE-2020-1885: Oculus Desktop

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file.

Affected products

  • Oculus Desktop: before 1.44.0.32849 (fixed in 1.44.0.32849)

Published 2020-04-08. Last modified 2026-06-17.