First published: Fri Mar 08 2019(Updated: )
A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine by loading an image, such as a DLL, with a long path.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CyberArk Endpoint Privilege Manager | <10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9627 is a buffer overflow vulnerability in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7.
CVE-2019-9627 allows an attacker to escalate privileges by loading an image with a long path, such as a DLL, without requiring Administrator privileges.
CVE-2019-9627 has a severity rating of 7 out of 10.
To fix CVE-2019-9627, update CyberArk Endpoint Privilege Manager to version 10.7 or above.
Yes, you can find more information about CVE-2019-9627 at the following links: [SecurityFocus BID 107387](http://www.securityfocus.com/bid/107387), [SecurityFocus BID 107852](http://www.securityfocus.com/bid/107852), [NCC Group Technical Advisory](https://www.nccgroup.trust/us/our-research/technical-advisory-cyberark-epm-non-paged-pool-buffer-overflow/).