Description
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execute arbitrary code with system privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4390 | ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execute arbitrary code with system privileges. |
References
History
No history.
Status: PUBLISHED
Assigner: krcert
Published:
Updated: 2024-08-04T23:32:55.207Z
Reserved: 2019-06-13T00:00:00.000Z
Link: CVE-2019-12808
No data.
Status : Modified
Published: 2019-08-13T20:15:11.947
Modified: 2024-11-21T04:23:37.293
Link: CVE-2019-12808
No data.
OpenCVE Enrichment
No data.
EUVD