CVE-2019-6145 Vulnerability Details

  /     /     /  

CVE-2019-6145 Metadata Quick Info

CVE Published: 20/09/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: forcepoint | Vendor: Forcepoint | Product: Forcepoint VPN Client for Windows
Status : PUBLISHED

CVE-2019-6145 Description

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Unquoted search path vulnerability
Source: Forcepoint

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).