PT-2020-9165 · Paessler · Prtg Network Monitor
Javier Jimenez
·
Published
2020-03-17
·
Updated
2021-06-29
·
CVE-2019-11074
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PRTG Network Monitor versions 19.1.49 and below
Description
A Write to Arbitrary Location in Disk issue exists due to insufficient sanitisation when passing arguments to the
phantomjs.exe binary, allowing attackers to place files in arbitrary locations with SYSTEM privileges. Remote authenticated administrators can exploit this by creating a new HTTP Full Web Page Sensor and setting specific settings when executing the sensor.Recommendations
For versions 19.1.49 and below, update to a version above 19.1.49 to resolve the issue. As a temporary workaround, consider restricting access to the
phantomjs.exe binary and the HTTP Full Web Page Sensor to minimize the risk of exploitation.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prtg Network Monitor