PT-2019-13409 · Microsoft+1 · Windows+1
Published
2019-10-25
·
Updated
2019-10-30
·
CVE-2019-13546
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IntelliSpace Perinatal versions K and prior
Description
A vulnerability in the IntelliSpace Perinatal application environment could allow an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user, to break out from the containment of the application and access unauthorized resources from the Windows operating system as a limited-access Windows user. Additionally, due to potential Windows vulnerabilities, it may be possible for attackers to use other methods to escalate privileges on the operating system.
Recommendations
For versions K and prior, consider restricting access to the application environment to minimize the risk of exploitation, and apply any available Windows security updates to reduce the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellispace Perinatal
Windows