CVE-2019-5631: Rapid7 InsightAppSec Local Privilege Escalation
The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-5631?
CVE-2019-5631 is a DLL injection vulnerability in the 'prunsrv.exe' component of Rapid7 InsightAppSec broker, which allows a local user to elevate their privileges.
Who is affected by CVE-2019-5631?
Rapid7 InsightAppSec versions up to and including 2019.06.24 are affected by CVE-2019-5631.
How severe is CVE-2019-5631?
CVE-2019-5631 has a severity rating of 7.8 (Critical).
How can CVE-2019-5631 be exploited?
CVE-2019-5631 can be exploited by a local user of the system who is already authenticated to the operating system.
Is there a fix for CVE-2019-5631?
Rapid7 has released a fix for CVE-2019-5631. It is recommended to update to the latest version of Rapid7 InsightAppSec to mitigate this vulnerability.