PT-2019-13001 · Microsoft+1 · Windows+1

Nulsect0R

·

Published

2019-08-20

·

Updated

2020-08-24

·

CVE-2019-12889

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SailPoint Desktop Password Reset version 7.2
Description An unauthenticated privilege escalation issue exists, allowing a user with local access to the Windows logon screen to escalate their privileges to NT AUTHORITYSystem. To exploit this, an attacker needs local access to the machine and must disconnect it from the local network/WAN, then connect it to an internet-facing access point/network. The attacker can then execute the password-reset functionality, exposing a web browser. By browsing to a site that calls local Windows system functions, such as file upload, the local file system is exposed, enabling the launch of a privileged command shell.
Recommendations For SailPoint Desktop Password Reset version 7.2, as a temporary workaround, consider restricting local access to the Windows logon screen and limiting the ability to disconnect from and reconnect to different networks until a patch is available. Additionally, restrict access to the password-reset functionality to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12889

Affected Products

Sailpoint Desktop Password Reset
Windows