CVE-2019-14969: High severity netwrix auditor vulnerability
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the invoking process (in this case, granting Authenticated Users full access over the target file). This vulnerability can be triggered by a low-privileged user to perform DLL Hijacking/Binary Planting attacks and ultimately execute code as NT AUTHORITY\SYSTEM with the help of Symbolic Links.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14969?
CVE-2019-14969 is a vulnerability in Netwrix Auditor before version 9.8 that allows unauthorized access to sensitive files due to insecure permissions and lack of proper impersonation.
How severe is CVE-2019-14969?
CVE-2019-14969 has a severity score of 7.8 out of 10, indicating a high severity.
How does the vulnerability in CVE-2019-14969 work?
The vulnerability in CVE-2019-14969 allows an attacker to gain unauthorized access to sensitive files by exploiting insecure permissions and lack of proper impersonation in Netwrix Auditor before version 9.8.
What software is affected by CVE-2019-14969?
Netwrix Auditor versions up to and excluding 9.8 are affected by CVE-2019-14969.
Is there a fix for CVE-2019-14969?
Yes, upgrading Netwrix Auditor to version 9.8 or newer will fix the vulnerability.