First published: Thu Nov 21 2019(Updated: )
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Firewall Analyzer | =12.4-124072 | |
Zohocorp ManageEngine OpManager | =12.4-build124072 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17421 is a vulnerability in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 that allows local users to elevate privileges to root by overwriting a file with a malicious payload.
CVE-2019-17421 has a severity score of 7.8, which is considered high.
To fix CVE-2019-17421, it is recommended to update Zoho ManageEngine OpManager and Firewall Analyzer to the latest version.
You can find more information about CVE-2019-17421 on the Vastart blog, Twitter handle (@va_start), and the ManageEngine website.
The CWE ID for CVE-2019-17421 is 276.