Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19895

Опубликовано: 23 янв. 2020
Источник: nvd
CVSS3: 8.8
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ixpdata:easyinstall:6.2.13723:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

github
около 3 лет назад

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732