CVE-2019-18631
Last modified
CVE-2019-18631 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute arbitrary code inside the Centrify process via (1) a crafted application that makes a pipe connection to the process and sends malicious serialized data or (2) a crafted Microsoft Management Console snap-in control file.. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute arbitrary code inside the Centrify process via (1) a crafted application that makes a pipe connection to the process and sends malicious serialized data or (2) a crafted Microsoft Management Console snap-in control file.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Centrify | Authentication Service | 3.4.0 |
| Centrify | Authentication Service | 3.4.1 |
| Centrify | Authentication Service | 3.4.2 |
| Centrify | Authentication Service | 3.4.3 |
| Centrify | Authentication Service | 3.5.0 |
| Centrify | Authentication Service | 3.5.1 |
| Centrify | Authentication Service | 3.5.2 |
| Centrify | Authentication Service | 3.6.0 |
| Centrify | Privilege Elevation Service | 3.4.0 |
| Centrify | Privilege Elevation Service | 3.4.1 |
| Centrify | Privilege Elevation Service | 3.4.2 |
| Centrify | Privilege Elevation Service | 3.4.3 |
| Centrify | Privilege Elevation Service | 3.5.0 |
| Centrify | Privilege Elevation Service | 3.5.1 |
| Centrify | Privilege Elevation Service | 3.5.2 |
| Centrify | Privilege Elevation Service | 3.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-18631?
How severe is CVE-2019-18631?
How do I fix CVE-2019-18631?
Are you affected by CVE-2019-18631?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
