Vulnerability Description
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Firewall Analyzer | 12.4 |
| Zohocorp | Manageengine Opmanager | 12.4 |
Related Weaknesses (CWE)
References
- https://blog.vastart.dev/2019/11/cve-2019-17421-privilege-escalation.htmlThird Party Advisory
- https://twitter.com/va_startExploitThird Party Advisory
- https://www.manageengine.com/products/firewall/security-updates/cve-2019-17421.hPatchVendor Advisory
- https://blog.vastart.dev/2019/11/cve-2019-17421-privilege-escalation.htmlThird Party Advisory
- https://twitter.com/va_startExploitThird Party Advisory
- https://www.manageengine.com/products/firewall/security-updates/cve-2019-17421.hPatchVendor Advisory
FAQ
What is CVE-2019-17421?
CVE-2019-17421 is a vulnerability with a CVSS score of 7.8 (HIGH). Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting ...
How severe is CVE-2019-17421?
CVE-2019-17421 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17421?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Firewall Analyzer, Zohocorp Manageengine Opmanager.