Permissions, Privileges, and Access Controls in MongoDB - CVE-2019-2390
Published: September 24, 2019
MongoDB
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the way MongoDB uses OpenSSL, when installed on Windows. A local unprivileged user with ability to create OpenSSL configuration files in a fixed location can modify OpenSSL configuration files and execute arbitrary code on the system via utility programs, shipped with MongoDB server.
Successful exploitation of the vulnerability requires that a legitimate user runs MongoDB utility programs.