// For flags

CVE-2019-12042

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.

Los permisos no seguros del objeto de la sección Global\PandaDevicesAgentSharedMemory y el evento Global\PandaDevicesAgentSharedMemoryChange en los productos de Panda antes de la versión 18.07.03, permiten que los atacantes pongan en cola un evento (como una cadena cifrada JSON) al servicio del sistema AgentSvc.exe, lo que lleva a una escalada de privilegios cuando el evento CmdLineExecute está en cola. Esto afecta a Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection y Panda Internet Security.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-05-13 CVE Reserved
  • 2019-05-23 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-10-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Pandasecurity
Search vendor "Pandasecurity"
Panda Antivirus
Search vendor "Pandasecurity" for product "Panda Antivirus"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Antivirus" and version " < 18.07.03"
-
Affected
Pandasecurity
Search vendor "Pandasecurity"
Panda Antivirus Pro
Search vendor "Pandasecurity" for product "Panda Antivirus Pro"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Antivirus Pro" and version " < 18.07.03"
-
Affected
Pandasecurity
Search vendor "Pandasecurity"
Panda Dome
Search vendor "Pandasecurity" for product "Panda Dome"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Dome" and version " < 18.07.03"
-
Affected
Pandasecurity
Search vendor "Pandasecurity"
Panda Global Protection
Search vendor "Pandasecurity" for product "Panda Global Protection"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Global Protection" and version " < 18.07.03"
-
Affected
Pandasecurity
Search vendor "Pandasecurity"
Panda Gold Protection
Search vendor "Pandasecurity" for product "Panda Gold Protection"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Gold Protection" and version " < 18.07.03"
-
Affected
Pandasecurity
Search vendor "Pandasecurity"
Panda Internet Security
Search vendor "Pandasecurity" for product "Panda Internet Security"
< 18.07.03
Search vendor "Pandasecurity" for product "Panda Internet Security" and version " < 18.07.03"
-
Affected