Vulnerability Description
Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tinywall | Tinywall | < 2.1.13 |
Related Weaknesses (CWE)
References
- https://gist.github.com/pylorak/7df52c9325614676e07782dbe4e81582Third Party Advisory
- https://www.wilderssecurity.com/threads/beta-testing-tinywall.309739/page-62#posThird Party Advisory
- https://gist.github.com/pylorak/7df52c9325614676e07782dbe4e81582Third Party Advisory
- https://www.wilderssecurity.com/threads/beta-testing-tinywall.309739/page-62#posThird Party Advisory
FAQ
What is CVE-2019-19470?
CVE-2019-19470 is a vulnerability with a CVSS score of 7.8 (HIGH). Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and incl...
How severe is CVE-2019-19470?
CVE-2019-19470 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19470?
Check the references section above for vendor advisories and patch information. Affected products include: Tinywall Tinywall.