| |
Vulnerability CVE-2019-19364
Published: 2019-12-04
Description: |
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don???t exist from its current directory; by doing so, an attacker can quickly escalate its privileges. |
Type:
CWE-426 (Untrusted Search Path)
CVSS2 => (AV:L/AC:M/Au:N/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.4/10 |
6.4/10 |
3.4/10 |
Exploit range |
Attack complexity |
Authentication |
Local |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://gist.github.com/Eli-Paz/482b514320009f3e76ea712cde3bc350
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|