#VU24771 Incorrect default permissions in EasyInstall - CVE-2019-19896
Published: January 30, 2020
EasyInstall
IXP Data
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows
modification of directories and files (e.g., bat-scripts), which allows remote authenticated attacker to execute arbitrary code in the context of "NT AUTHORITYSYSTEM" on the target
server and clients.