PT-2019-12151 · Mirasys · Mirasys Vms

Published

2019-08-22

·

Updated

2019-08-30

·

CVE-2019-11031

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mirasys VMS versions prior to 7.6.1 Mirasys VMS versions 8.x prior to 8.3.2
Description The issue arises from the mishandling of the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can exploit this by uploading files with a Setup-Files action and then executing these files with SYSTEM privileges.
Recommendations For versions prior to 7.6.1, update to version 7.6.1 or later. For versions 8.x prior to 8.3.2, update to version 8.3.2 or later.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11031

Affected Products

Mirasys Vms