Exposed dangerous method or function in Crowd Server - CVE-2019-11580

 

Exposed dangerous method or function in Crowd Server - CVE-2019-11580

Published: June 7, 2019 / Updated: August 12, 2021


Vulnerability identifier: #VU18716
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11580
CWE-ID: CWE-749
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to incorrectly enabled pdkinstall development plugin in release builds. A remote unauthenticated attacker can install arbitrary plugin and gain full control over the affected system.

Successful exploitation of the vulnerability may allow remote code execution.


Affected software

Crowd Server

How to mitigate CVE-2019-11580

Install updates from vendor's website.

Crowd Server - addressed in versions 3.0.5, 3.1.6, 3.2.8, 3.3.5, 3.4.4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins