ZeroHour

CVE-2019-5443

CVSS 3.1
7.8 high
EPSS
<1%p51
Published
()
Modified
Description

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

Vendors
haxxoraclenetapp
Products
curl, enterprise manager ops center, http server, mysql server, oss support tools, oncommand insight, oncommand unified manager, oncommand workflow automation, snapcenter
Weakness
CWE-94, CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.