First published: Thu May 23 2019(Updated: )
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Panda Security | <18.07.03 | |
Panda Security Panda Antivirus Pro 2015 | <18.07.03 | |
Panda Dome | <18.07.03 | |
Panda Security Panda Global Protection | <18.07.03 | |
Panda Security Panda Gold Protection 2015 | <18.07.03 | |
Panda Security | <18.07.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12042 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2019-12042, update your Panda products to version 18.07.03 or later.
CVE-2019-12042 allows attackers to execute arbitrary code with elevated privileges by manipulating shared memory.
CVE-2019-12042 affects all Panda products prior to version 18.07.03.
CVE-2019-12042 can be exploited by local attackers with the ability to interact with the Panda service.