CVE-2019-1932
Last modified
CVE-2019-1932 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows filesystem. A successful exploit could allow the attacker to execute the code with the privileges of the AMP service.
Metrics
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Advanced Malware Protection For Endpoints | 6.2\(3\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1932?
How severe is CVE-2019-1932?
How do I fix CVE-2019-1932?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19314GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored severa…7.5
- CVE-2019-19315NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used…7.1
- CVE-2019-19316When using the Azure backend with a shared access signature …7.5
- CVE-2019-19317lookupName in resolve.c in SQLite 3.30.1 omits bits from the…9.8
- CVE-2019-19318In the Linux kernel 5.3.11, mounting a crafted btrfs image t…4.4
- CVE-2019-19319In the Linux kernel before 5.2, a setxattr operation, after …6.5
- CVE-2019-19324Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported …7.5
- CVE-2019-19325SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5…6.1
- CVE-2019-19326Silverstripe CMS sites through 4.4.4 which have opted into H…5.9
- CVE-2019-19327ui/ResultView.js in Wikibase Wikidata Query Service GUI befo…6.1
- CVE-2019-19328ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service …6.1
- CVE-2019-19329In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT…6.1
Are you affected by CVE-2019-1932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
