PT-2019-13001 · Microsoft+1 · Windows+1
Nulsect0R
·
Published
2019-08-20
·
Updated
2020-08-24
·
CVE-2019-12889
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SailPoint Desktop Password Reset version 7.2
Description
An unauthenticated privilege escalation issue exists, allowing a user with local access to the Windows logon screen to escalate their privileges to NT AUTHORITYSystem. To exploit this, an attacker needs local access to the machine and must disconnect it from the local network/WAN, then connect it to an internet-facing access point/network. The attacker can then execute the password-reset functionality, exposing a web browser. By browsing to a site that calls local Windows system functions, such as file upload, the local file system is exposed, enabling the launch of a privileged command shell.
Recommendations
For SailPoint Desktop Password Reset version 7.2, as a temporary workaround, consider restricting local access to the Windows logon screen and limiting the ability to disconnect from and reconnect to different networks until a patch is available. Additionally, restrict access to the password-reset functionality to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sailpoint Desktop Password Reset
Windows