Unrated severityNVD Advisory· Published Jun 29, 2019· Updated Aug 4, 2024
CVE-2019-13035
CVE-2019-13035
Description
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Artica/Pandora FMSdescription
- Range: 7.0 NG before 735
Patches
Vulnerability mechanics
References
1- github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-008.mdmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.