Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11030

Опубликовано: 22 авг. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mirasys:mirasys_vms:*:*:*:*:*:*:*:*
Версия до 7.6.1 (исключая)
cpe:2.3:a:mirasys:mirasys_vms:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.3.2 (исключая)

EPSS

Процентиль: 58%
0.00368
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502

Связанные уязвимости

github
больше 3 лет назад

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.

EPSS

Процентиль: 58%
0.00368
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502