CVE-2019-12091: Netskope client command injections vulnerability
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling function in this service suffers from command injection vulnerability. Local users can use this vulnerability to execute code with NT\SYSTEM privilege.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-12091?
CVE-2019-12091 is a vulnerability in the Netskope client service that allows local users to execute arbitrary commands with NT\SYSTEM privilege.
How severe is CVE-2019-12091?
CVE-2019-12091 has a severity rating of 7.8 (high).
Which versions of Netskope are affected by CVE-2019-12091?
CVE-2019-12091 affects Netskope client service versions 57 before 57.2.0.219 and versions 60 before 60.2.0.214.
How can local users exploit CVE-2019-12091?
Local users can exploit CVE-2019-12091 to execute arbitrary commands by leveraging the command injection vulnerability in the Netskope client service.
Where can I find more information about CVE-2019-12091?
You can find more information about CVE-2019-12091 in the following references: [1] [2] [3]