PT-2019-17789 · Rapid7 · Rapid7 Insight Agent

Florian Bogner

·

Publicado

2019-07-13

·

Atualizado

2021-12-14

·

CVE-2019-5629

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rapid7 Insight Agent versions 2.6.3 and prior
Description The issue is related to an uncontrolled DLL search path, allowing a malicious local user to elevate to SYSTEM privileges. This occurs when the Python interpreter attempts to load python3.dll from a writable location, specifically "C:DLLspython3.dll".
Recommendations For Rapid7 Insight Agent versions 2.6.3 and prior, update to version 2.6.4 to resolve the issue.

Exploit

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-5629

Produtos afetados

Rapid7 Insight Agent