CVE-2019-17066
Last modified
CVE-2019-17066 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Workspace Control | < 10.4.40.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17066?
How severe is CVE-2019-17066?
How do I fix CVE-2019-17066?
Are you affected by CVE-2019-17066?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
