#VU24769 Input validation error in EasyInstall - CVE-2019-19895
Published: January 30, 2020
EasyInstall
IXP Data
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the Lateral Movement (using the Agent Service) against other users on a client system. A remote authenticated attacker can modify "%SYSTEMDRIVE%IXPSW[PACKAGE_CODE]EveryLogon.bat" to achieve this movement and execute code in the context of other users.