Vulnerability Description
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pearsonvue | Console 8 | < 2018-06-26 |
| Pearsonvue | Iqsystem 7 | < 2018-06-26 |
Related Weaknesses (CWE)
References
- https://certiport.pearsonvue.com/Support/Console-system-updatesVendor Advisory
- https://computeco.de/2018-07-29_1.htmlMitigationThird Party Advisory
- https://certiport.pearsonvue.com/Support/Console-system-updatesVendor Advisory
- https://computeco.de/2018-07-29_1.htmlMitigationThird Party Advisory
FAQ
What is CVE-2018-12989?
CVE-2018-12989 is a vulnerability with a CVSS score of 6.7 (MEDIUM). The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator...
How severe is CVE-2018-12989?
CVE-2018-12989 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12989?
Check the references section above for vendor advisories and patch information. Affected products include: Pearsonvue Console 8, Pearsonvue Iqsystem 7.