← Back

CVE-2019-11031

nvd nist
Published: Aug 22, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

Affected (2)

Products: Mirasys: Mirasys Vms
1 product
Mirasys Vms
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Mirasys
Before 7.6.1
From 8.0.0 to 8.3.2

Timeline

No history available yet.