CVE-2019-9627: Buffer Overflow
A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine by loading an image, such as a DLL, with a long path.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9627?
CVE-2019-9627 is a buffer overflow vulnerability in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7.
How does CVE-2019-9627 allow privilege escalation?
CVE-2019-9627 allows an attacker to escalate privileges by loading an image with a long path, such as a DLL, without requiring Administrator privileges.
How severe is CVE-2019-9627?
CVE-2019-9627 has a severity rating of 7 out of 10.
How can I fix CVE-2019-9627?
To fix CVE-2019-9627, update CyberArk Endpoint Privilege Manager to version 10.7 or above.
Are there any references related to CVE-2019-9627?
Yes, you can find more information about CVE-2019-9627 at the following links: [SecurityFocus BID 107387](http://www.securityfocus.com/bid/107387), [SecurityFocus BID 107852](http://www.securityfocus.com/bid/107852), [NCC Group Technical Advisory](https://www.nccgroup.trust/us/our-research/technical-advisory-cyberark-epm-non-paged-pool-buffer-overflow/).