First published: Wed Dec 04 2019(Updated: )
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sony Catalyst Browse | <=2019.1 | |
Sony Catalyst Production Suite | <=2019.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19364.
The severity of CVE-2019-19364 is high with a CVSS score of 7.8.
The Catalyst Browse and Catalyst Production Suite versions up to 2019.1 are affected by CVE-2019-19364.
The vulnerability is in the form of DLL Hijacking.
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe and CatalystBrowseSuite.2019.1.exe installers run.