Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5631

Опубликовано: 19 авг. 2019
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:insightappsec:*:*:*:*:*:*:*:*
Версия до 2019.06.24 (включая)

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-427
CWE-426

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-427
CWE-426