CVE-2019-18631
Summary
| CVE | CVE-2019-18631 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-05 16:15:00 UTC |
| Updated | 2021-09-13 10:52:00 UTC |
| Description | The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute arbitrary code inside the Centrify process via (1) a crafted application that makes a pipe connection to the process and sends malicious serialized data or (2) a crafted Microsoft Management Console snap-in control file. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Centrify | Authentication Service | 3.4.0 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.1 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.2 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.3 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.0 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.1 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.2 | All | All | All |
| Application | Centrify | Authentication Service | 3.6.0 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.0 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.1 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.2 | All | All | All |
| Application | Centrify | Authentication Service | 3.4.3 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.0 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.1 | All | All | All |
| Application | Centrify | Authentication Service | 3.5.2 | All | All | All |
| Application | Centrify | Authentication Service | 3.6.0 | All | All | All |
| Application | Centrify | Infrastructure Services | 18.11 | All | All | All |
| Application | Centrify | Infrastructure Services | 18.8 | All | All | All |
| Application | Centrify | Infrastructure Services | 19.6 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.0 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.1 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.2 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.3 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.0 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.1 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.2 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.6.0 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.0 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.1 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.2 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.4.3 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.0 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.1 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.5.2 | All | All | All |
| Application | Centrify | Privilege Elevation Service | 3.6.0 | All | All | All |
| Application | Certify | Infrastructure Services | 18.11 | All | All | All |
| Application | Certify | Infrastructure Services | 18.8 | All | All | All |
| Application | Certify | Infrastructure Services | 19.6 | All | All | All |
| Application | Certify | Infrastructure Services | 18.11 | All | All | All |
| Application | Certify | Infrastructure Services | 18.8 | All | All | All |
| Application | Certify | Infrastructure Services | 19.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KB-22420: Centrify Agent for Windows - Remote Code Execution Vulnerability | CONFIRM | centrify.force.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.