High severity8.8NVD Advisory· Published Apr 30, 2019· Updated Jun 17, 2026
CVE-2019-9486
CVE-2019-9486
Description
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.
Affected products
5cpe:2.3:a:strato:hidrive_desktop_client:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:strato:hidrive_desktop_client:*:*:*:*:*:windows:*:*range: <=5.0.1.0
- (no CPE)range: 5.0.1.0
cpe:2.3:a:telekom:magentacloud:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:telekom:magentacloud:*:*:*:*:*:*:*:*range: <=5.7.0.0
- (no CPE)range: <=5.7.0.0
Patches
Vulnerability mechanics
References
1- zer0-day.pw/articles/2019-04/HiDrive-LPE-via-Insecure-WCF-endpointnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.