CVE-2019-5443

Description

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl engine) on invocation. If that curl is invoked by a privileged user it can do anything it wants.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.953

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2019-5443 are affected in Curl For Windows 7.65.1Windows
Vulnerabilities CVE-2019-5481,CVE-2019-5482,CVE-2019-5443 are fixed in Curl For Windows 7.66.0Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation 2.3Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234