CVE-2019-9745
Summary
| CVE | CVE-2019-9745 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-14 15:15:00 UTC |
| Updated | 2019-10-21 13:37:00 UTC |
| Description | CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used to import data from CRM software using plugins (.dll files). The plugin to import data from the EXQUISE software (DatasourceExquiseExporter.dll) can be persuaded to start arbitrary programs (including batch files) that are executed using the same privileges as Recognition Update Client Service (NT AUTHORITY\SYSTEM), thus elevating privileges. This occurs because a higher-privileged process executes scripts from a directory writable by a lower-privileged user. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudcti | Hip Integrator Recognition Configuration Tool | - | All | All | All |
| Application | Cloudcti | Hip Integrator Recognition Configuration Tool | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CloudCTI | MISC | www.cloudcti.nl | Vendor Advisory |
| CVE-2019-9745/README.md at master · KPN-CISO/CVE-2019-9745 · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.