PT-2019-15542 · Centrify+1 · Centrify Authentication/Privilege Elevation Services+1

Published

2019-11-05

·

Updated

2021-09-13

·

CVE-2019-18631

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Centrify Authentication and Privilege Elevation Services versions 3.4.0 through 3.6.0
Description The issue arises from improper handling of an unspecified exception during the use of partially trusted assemblies to serialize input data. This allows attackers to execute arbitrary code inside the Centrify process. The exploitation can occur through a crafted application that makes a pipe connection to the process and sends malicious serialized data, or through a crafted Microsoft Management Console snap-in control file.
Recommendations For versions 3.4.0 through 3.6.0, consider restricting access to the Centrify process to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using partially trusted assemblies for serializing input data.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18631

Affected Products

Centrify Authentication/Privilege Elevation Services
Management Console