PT-2019-12074 · Netskope · Netskope Client Service

Publicado

2019-09-26

·

Atualizado

2021-09-14

·

CVE-2019-10882

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netskope client service versions prior to 57.2.0.219 Netskope client service versions prior to 60.2.0.214
Description The issue is related to a stack-based buffer overflow in the doHandshakefromServer function. This function is part of the connection handling mechanism in the Netskope client service, which runs with NTSYSTEM privilege and accepts network connections from localhost. Local users can exploit this to cause a crash of the service, potentially leading to additional system impact.
Recommendations For versions prior to 57.2.0.219, update to version 57.2.0.219 or later. For versions prior to 60.2.0.214, update to version 60.2.0.214 or later. As a temporary workaround, consider disabling the doHandshakefromServer function until a patch is available.

Correção

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10882

Produtos afetados

Netskope Client Service