CVE-2019-12091 HIGH

CVE-2019-12091: Netskope client command injections vulnerability

Vendor Netskope
Product Netskope client
Weakness CWE-78
Published September 26, 2019
Last update August 4, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling function in this service suffers from command injection vulnerability. Local users can use this vulnerability to execute code with NT\SYSTEM privilege.

Key dates

02Disclosure timeline

September 26, 2019 CVE published
August 4, 2024 Record updated