CVE-2019-9486

UnknownEPSS 2.29%

Last modified

CVE-2019-9486 is a vulnerability of currently unknown severity. STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. EPSS estimates a 2.29% chance of exploitation in the next 30 days.

Description

STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

Metrics

EPSS Probability
2.29%

81.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
StratoHidrive Desktop Client<= 5.0.1.0
TelekomMagentacloud<= 5.7.0.0
Ionos1\&1 Online Storage<= 6.1.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-9486?
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.
How severe is CVE-2019-9486?
Severity scoring for CVE-2019-9486 is pending analysis. The EPSS model estimates a 2.29% probability of exploitation in the next 30 days.
How do I fix CVE-2019-9486?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-9486?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST