CVE-2018-19204: Input Validation
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for PRTG Network Monitor?
The vulnerability ID for PRTG Network Monitor is CVE-2018-19204.
What is the severity of CVE-2018-19204?
The severity of CVE-2018-19204 is critical with a CVSS score of 8.8.
What is affected by CVE-2018-19204?
PRTG Network Monitor versions up to 18.3.44.2054 are affected by CVE-2018-19204.
How can an attacker exploit CVE-2018-19204?
An attacker with read-write privileges can execute arbitrary code and OS commands with system privileges through the mishandling of the 'proxyport_' POST parameter in an HTTP Advanced Sensor.
Is there a fix for CVE-2018-19204?
Yes, upgrading to PRTG Network Monitor version 18.3.44.2054 or later fixes CVE-2018-19204.