CVE-2019-12042: Critical severity panda security vulnerability
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12042?
CVE-2019-12042 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2019-12042?
To fix CVE-2019-12042, update your Panda products to version 18.07.03 or later.
What impact does CVE-2019-12042 have on affected systems?
CVE-2019-12042 allows attackers to execute arbitrary code with elevated privileges by manipulating shared memory.
Which versions of Panda products are affected by CVE-2019-12042?
CVE-2019-12042 affects all Panda products prior to version 18.07.03.
Who can exploit CVE-2019-12042?
CVE-2019-12042 can be exploited by local attackers with the ability to interact with the Panda service.