Multiple vulnerabilities in Sony VAIO Update



Published: 2019-06-25
Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2019-5981
CVE-2019-5982
CWE-ID CWE-264
CWE-300
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Subscribe
Sony VAIO Update
Client/Desktop applications / Other client software

Vendor Sony Corporation

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU18885

Risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5981

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local user to execute arbitrary file with administrative privileges.

The vulnerability exists due to unspecified error that can lead to execution of arbitrary file with administrative privileges.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Sony VAIO Update: 5.1.1.04090 - 7.3.0.03150

External links

http://jvn.jp/en/jp/JVN13555032/index.html
http://www.sony.com/electronics/support/articles/00228777


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Man-in-the-Middle (MitM) attack

EUVDB-ID: #VU18896

Risk: Low

CVSSv3.1: 6.2 [CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5982

CWE-ID: CWE-300 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform man-in-the-middle (MitM) attack.
The vulnerability exists due to software does not validate integrity of the downloaded file before executing it. A remote attacker with ability to perform man-in-the-middle (MitM) attack can execute arbitrary code on the affected system. 

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Sony VAIO Update: 5.1.1.04090 - 7.3.0.03150

External links

http://jvn.jp/en/jp/JVN13555032/index.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###