High severity7.8NVD Advisory· Published Jul 13, 2019· Updated Jun 17, 2026
CVE-2019-5629
CVE-2019-5629
Description
Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 2.6.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*range: <=2.6.3
- (no CPE)range: <=2.6.3
- (no CPE)range: 2.6.3 and prior
Patches
Vulnerability mechanics
References
5- bogner.sh/2019/06/local-privilege-escalation-in-rapid7s-windows-insight-idr-agent/nvdExploitThird Party Advisory
- packetstormsecurity.com/files/153159/Rapid7-Windows-InsightIDR-Agent-2.6.3.14-Local-Privilege-Escalation.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Jun/13nvdMailing ListThird Party Advisory
- help.rapid7.com/insightagent/release-notes/archive/2019/05/nvdThird Party Advisory
- seclists.org/bugtraq/2019/Jun/0nvdIssue TrackingMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.