CVE-2019-7590
If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Affected
- johnsoncontrols/exacqvision server
- Source
- productsecurity@jci.com
References
- http://www.securityfocus.com/bid/109307Third Party Advisory, VDB Entry
- https://gallery.technet.microsoft.com/scriptcenter/Windows-Unquoted-Service-190f0341Patch, Third Party Advisory
- https://packetstormsecurity.com/files/152128/exacqVision-9.8-Unquoted-Service-Path-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesMitigation, Vendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-199-01Third Party Advisory, US Government Resource
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5515.phpThird Party Advisory
- http://www.securityfocus.com/bid/109307Third Party Advisory, VDB Entry
- https://gallery.technet.microsoft.com/scriptcenter/Windows-Unquoted-Service-190f0341Patch, Third Party Advisory
- https://packetstormsecurity.com/files/152128/exacqVision-9.8-Unquoted-Service-Path-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesMitigation, Vendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-199-01Third Party Advisory, US Government Resource
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5515.phpThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.