CVE-2019-18910: OS Command Injection
Published Nov 22, 2019
·Updated
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.
Affected Software
4 affected components
HP ThinPro=6.2
HP ThinPro=6.2.1
HP ThinPro=7.0
HP ThinPro=7.1
Event History
Nov 22, 2019
CVE Published
via MITRE·09:23 PM
Data Sourced
via MITRE·09:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-18910?
CVE-2019-18910 is a vulnerability in the Citrix Receiver wrapper function that allows an attacker to inject commands and execute them with local user privileges.
2
What software is affected by CVE-2019-18910?
HP ThinPro versions 6.2, 6.2.1, 7.0, and 7.1 are affected by CVE-2019-18910.
3
How severe is CVE-2019-18910?
CVE-2019-18910 has a severity rating of 6.8, which is considered medium.
4
How can an attacker exploit CVE-2019-18910?
An attacker can exploit CVE-2019-18910 by injecting commands that will execute with local user privileges.
5
Is there a fix for CVE-2019-18910?
Yes, a fix for CVE-2019-18910 is available. Please refer to the HP ThinPro support documentation for instructions on how to apply the fix.