PT-2019-17791 · Rapid7 · Insightappsec

Published

2019-08-19

·

Updated

2023-03-29

·

CVE-2019-5631

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rapid7 InsightAppSec versions 2019.06.24 and prior
Description The issue is related to a DLL injection vulnerability in the 'prunsrv.exe' component. A local user who is already authenticated to the operating system can exploit this to elevate their privileges to the level of InsightAppSec, usually SYSTEM.
Recommendations For versions 2019.06.24 and prior, update to a version later than 2019.06.24 to resolve the issue. As a temporary workaround, consider restricting access to the 'prunsrv.exe' component to minimize the risk of exploitation.

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2019-5631

Affected Products

Insightappsec