ZeroHour

CVE-2019-16861

CVSS 3.1
7.3 high
EPSS
<1%p31
Published
()
Modified
Description

Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary code at an elevated privilege on the local server.

Vendors
code42
Products
code42
Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.