TROYANOSYVIRUS
Back to CVEs

CVE-2019-17421

HIGH
7.8

Description

Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.

CVE Details

CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published11/21/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

zohocorp:manageengine_firewall_analyzerzohocorp:manageengine_opmanager

Weaknesses (CWE)

CWE-276

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.