CVE-2019-7590: exacqVision Server Unquoted Service Path
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7590?
The severity of CVE-2019-7590 is high with a score of 7.8.
How does CVE-2019-7590 affect ExacqVision Server?
CVE-2019-7590 affects ExacqVision Server versions 9.6 and 9.8.
What is the vulnerability in CVE-2019-7590?
The vulnerability in CVE-2019-7590 is an unquoted service path in ExacqVision Server's services 'exacqVisionServer', 'dvrdhcpserver', and 'mdnsresponder'.
How can an authenticated user exploit CVE-2019-7590?
If an authenticated user is able to insert code in their system root path, it potentially can be executed during the application startup, allowing them to escalate privileges.
Are there any references for CVE-2019-7590?
Yes, you can find more information about CVE-2019-7590 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/109307), [Microsoft TechNet](https://gallery.technet.microsoft.com/scriptcenter/Windows-Unquoted-Service-190f0341), and [Packet Storm Security](https://packetstormsecurity.com/files/152128/exacqVision-9.8-Unquoted-Service-Path-Privilege-Escalation.html).