Unrated severityNVD Advisory· Published Jul 6, 2019· Updated Nov 20, 2024
Cisco Advanced Malware Protection for Endpoints Windows Command Injection Vulnerability
CVE-2019-1932
Description
A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows filesystem. A successful exploit could allow the attacker to execute the code with the privileges of the AMP service.
Affected products
1- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-amp-commandinjmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.