A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine by loading an image, such as a DLL, with a long path.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/107387 | Broken Link |
http://www.securityfocus.com/bid/107852 | Broken Link |
https://www.nccgroup.trust/us/our-research/technical-advisory-cyberark-epm-non-paged-pool-buffer-overflow/ | Third Party Advisory |
Configurations
History
05 Apr 2022, 20:54
Type | Values Removed | Values Added |
---|---|---|
References | (BID) http://www.securityfocus.com/bid/107852 - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/107387 - Broken Link | |
CWE | CWE-787 |
Information
Published : 2019-03-08 19:29
Updated : 2024-02-04 20:20
NVD link : CVE-2019-9627
Mitre link : CVE-2019-9627
CVE.ORG link : CVE-2019-9627
JSON object : View
Products Affected
cyberark
- endpoint_privilege_manager
CWE
CWE-787
Out-of-bounds Write