← Back

CVE-2019-6008

nvd nist
Published: Dec 26, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and InsightSuiteAE (R1.01.00 ? R1.06.00)) allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges.

Affected (8)

8 products
Exaopc
Exaplog
Exaquantum
Exaquantum/batch
Exarqe
Exasmoc
Ga10
Insightsuiteae
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
From r1.01.00 to r3.77.00
From r1.10.00 to r3.30.00
From r1.10.00 to r3.02.00
From r1.01.00 to r2.50.40
All versions
All versions
From r1.01.01 to r3.05.01
From r1.01.00 to r1.06.00

References (4)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.