CVE-2020-5419: RabbitMQ arbitrary code execution using local binary planting
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.
Other sources
VMware RabbitMQ could allow a local authenticated attacker to execute arbitrary code on the system, caused by a Windows-specific binary planting security flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5419 vulnerability?
CVE-2020-5419 is a vulnerability in RabbitMQ versions 3.8.x prior to 3.8.7 that allows a local authenticated attacker with write privileges to execute arbitrary code on the system.
What is the severity of CVE-2020-5419?
CVE-2020-5419 has a severity rating of 7.8 (high).
How does CVE-2020-5419 affect VMware RabbitMQ?
CVE-2020-5419 affects VMware RabbitMQ versions 3.8.0 to 3.8.7.
How can an attacker exploit CVE-2020-5419?
To exploit CVE-2020-5419, an attacker needs write privileges to the RabbitMQ installation directory and local access to the system.
Is there a fix for CVE-2020-5419?
Yes, updating to RabbitMQ version 3.8.7 fixes the CVE-2020-5419 vulnerability.