PT-2020-9165 · Paessler · Prtg Network Monitor

Javier Jimenez

·

Published

2020-03-17

·

Updated

2021-06-29

·

CVE-2019-11074

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PRTG Network Monitor versions 19.1.49 and below
Description A Write to Arbitrary Location in Disk issue exists due to insufficient sanitisation when passing arguments to the phantomjs.exe binary, allowing attackers to place files in arbitrary locations with SYSTEM privileges. Remote authenticated administrators can exploit this by creating a new HTTP Full Web Page Sensor and setting specific settings when executing the sensor.
Recommendations For versions 19.1.49 and below, update to a version above 19.1.49 to resolve the issue. As a temporary workaround, consider restricting access to the phantomjs.exe binary and the HTTP Full Web Page Sensor to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11074

Affected Products

Prtg Network Monitor