Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19894

Опубликовано: 23 янв. 2020
Источник: nvd
CVSS3: 5.5
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ixpdata:easyinstall:6.2.13723:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00134
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-732

Связанные уязвимости

github
больше 3 лет назад

In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP.

EPSS

Процентиль: 33%
0.00134
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-732