High severity7.8NVD Advisory· Published Jul 8, 2019· Updated Jun 17, 2026
CVE-2019-13404
CVE-2019-13404
Description
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:python:python:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:python:python:*:*:*:*:*:*:*:*range: <=2.7.16
- (no CPE)range: <=2.7.16, <3.5
- Python/Pythondescription
Patches
Vulnerability mechanics
References
1- docs.python.org/2/faq/windows.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.