CVE-2019-17421

Incorrect file permissions on the packaged Nipper executable file.

 

Vulnerability Details
ImpactThe vulnerability enables local users to elevate privileges to root. Users can perform this action by executing malicious payload with Nipper executable files.
ReportedSep 8, 2019
Reported ByGuy Levin (@va_start)
FixedNov 26, 2019
Affected Builds

Builds till 124078

Builds 124081 to 124098

Fixed in

Builds 124079 and 124099

OverviewIncorrect file permissions on the packaged Nipper executable file
Recommended Fix

For builds till 124078: Upgrade to NCM Version 12.4.079.

For builds 124081 to 124098: Contact our support team in case of queries.

 

 

Description

A user detected incorrect file permissions on the packaged Nipper executable file in which allowed local users to elevate privileges to root by overwriting this file with a malicious payload.

We recommend that you upgrade to NCM Version 12.4.079 or contact our support team at to fix this issue.

Source and Acknowledgements

Find out more about CVE-2019-17421 from the CVE dictionary.

Need Help?

For clarification or corrections please contact our support team or email us at ncm-support@manageengine.com.