PT-2019-13409 · Microsoft+1 · Windows+1

Published

2019-10-25

·

Updated

2019-10-30

·

CVE-2019-13546

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IntelliSpace Perinatal versions K and prior
Description A vulnerability in the IntelliSpace Perinatal application environment could allow an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user, to break out from the containment of the application and access unauthorized resources from the Windows operating system as a limited-access Windows user. Additionally, due to potential Windows vulnerabilities, it may be possible for attackers to use other methods to escalate privileges on the operating system.
Recommendations For versions K and prior, consider restricting access to the application environment to minimize the risk of exploitation, and apply any available Windows security updates to reduce the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13546

Affected Products

Intellispace Perinatal
Windows