CVE-2019-11030
Last modified
CVE-2019-11030 is a vulnerability of currently unknown severity. Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. EPSS estimates a 1.98% chance of exploitation in the next 30 days.
Description
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mirasys | Mirasys Vms | < 7.6.1 |
| Mirasys | Mirasys Vms | >= 8.0.0, < 8.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11030?
How severe is CVE-2019-11030?
How do I fix CVE-2019-11030?
Are you affected by CVE-2019-11030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
