Vulnerability Description
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the invoking process (in this case, granting Authenticated Users full access over the target file). This vulnerability can be triggered by a low-privileged user to perform DLL Hijacking/Binary Planting attacks and ultimately execute code as NT AUTHORITY\SYSTEM with the help of Symbolic Links.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netwrix | Auditor | < 9.8 |
Related Weaknesses (CWE)
References
- https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-010.md
- https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-010.md
FAQ
What is CVE-2019-14969?
CVE-2019-14969 is a vulnerability with a CVSS score of 7.8 (HIGH). Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to th...
How severe is CVE-2019-14969?
CVE-2019-14969 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14969?
Check the references section above for vendor advisories and patch information. Affected products include: Netwrix Auditor.