First published: Tue Dec 24 2019(Updated: )
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Signal Signal-desktop | <1.29.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19954.
The severity of CVE-2019-19954 is high with a severity value of 7.3.
The affected software for CVE-2019-19954 is Signal Desktop before version 1.29.1 on Windows.
Local users can gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
No, Microsoft Windows is not vulnerable to CVE-2019-19954.