VYPR
Unrated severityNVD Advisory· Published Jan 23, 2020· Updated Aug 5, 2024

CVE-2019-19896

CVE-2019-19896

Description

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Weak permissions on the IXP$ share in IXP EasyInstall 6.2.13723 allow remote code execution as SYSTEM on the server and clients.

Vulnerability

In IXP EasyInstall version 6.2.13723, the default file permissions on the IXP$ share on the server are too permissive. This allows modification of directories and files, including .bat scripts, which are part of the Engine Service. The share is used by the RMM and deployment software, and the weak permissions exist by default, requiring no special configuration to be exploited [1].

Exploitation

An attacker with network access to the IXP$ share can modify or replace existing .bat script files or create new ones. The attacker does not need authentication to modify the share because the default permissions allow write access. The modified scripts are then executed by the Engine Service in the context of NT AUTHORITY\SYSTEM on the target server and potentially on connected clients [1].

Impact

Successful exploitation results in remote code execution as NT AUTHORITY\SYSTEM, the highest privilege level on Windows. The attacker can fully compromise the affected server and any clients that process the scripts from the share. This leads to complete loss of confidentiality, integrity, and availability of the system [1].

Mitigation

Not yet disclosed in the available references. The vendor (IXP) should apply proper access control lists (ACLs) to the IXP$ share to restrict write permissions to only authorized administrators. Users should review and lock down permissions on the share as a workaround until an official patch is released [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.