CVE-2019-19954: High severity signal desktop vulnerability
Published Dec 24, 2019
·Updated
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\nodemodules\.bin\wmic.exe file.
Affected Software
2 affected components
Signal Signal-Desktop<1.29.1
Microsoft Windows
Remediation
Patch Available
Event History
Dec 24, 2019
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-19954.
2
What is the severity of CVE-2019-19954?
The severity of CVE-2019-19954 is high with a severity value of 7.3.
3
What is the affected software for CVE-2019-19954?
The affected software for CVE-2019-19954 is Signal Desktop before version 1.29.1 on Windows.
4
How can local users gain privileges with CVE-2019-19954?
Local users can gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
5
Is Microsoft Windows vulnerable to CVE-2019-19954?
No, Microsoft Windows is not vulnerable to CVE-2019-19954.