Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11644

EPSS 0.40% · P61
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11644

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a local user can escalate their privileges through a DLL hijacking attack against the installer. The installer writes the file rm.exe to C:\Windows\Temp and then executes it. The rm.exe process then attempts to load several DLLs from its current directory. Non-admin users are able to write to this folder, so an attacker can create a malicious C:\Windows\Temp\OLEACC.dll file. When an admin runs the installer, rm.exe will execute the attacker's DLL in an elevated security context.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款F-Secure产品代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
F-Secure Anti-Virus等都是芬兰F-Secure公司的产品。F-Secure Anti-Virus是一套杀毒软件。F-Secure Internet Security是一套主要提供针对网络钓鱼和恶意软件防护的杀毒软件。F-Secure SAFE for Windows是一套基于Windows平台的杀毒软件。 多款F-Secure产品中的F-Secure安装程序存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。以下产品及版本受到影响:F-Secure SAF
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-11644

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11644

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-05-17 · 65 CVEs total

CVE-2019-0170Intel Dynamic Application Loader 缓冲区错误漏洞
CVE-2019-8928ZOHO ManageEngine Netflow Analyzer 跨站脚本漏洞
CVE-2018-7191Linux kernel tun子系统代码问题漏洞
CVE-2019-8926ZOHO ManageEngine Netflow Analyzer 跨站脚本漏洞
CVE-2019-8927ZOHO ManageEngine Netflow Analyzer 跨站脚本漏洞
CVE-2019-11085Intel i915 Graphics Kernel Mode Driver 输入验证错误漏洞
CVE-2019-0172Intel Unite Client 权限许可和访问控制问题漏洞
CVE-2019-0171Intel Quartus Software 权限许可和访问控制问题漏洞
CVE-2019-0138Intel ACU Wizard 权限许可和访问控制问题漏洞
CVE-2019-0132Intel Unite Client 输入验证错误漏洞
CVE-2019-11093Intel SCS Discovery Utility 代码问题漏洞
CVE-2019-0153Intel Converged Security and Management Engine 缓冲区错误漏洞
CVE-2019-0126Intel Xeon Scalable Processor和Intel Xeon Processor D Family 权限许可和访问控制问题漏洞
CVE-2019-0120多款Intel产品访问控制错误漏洞
CVE-2019-0119多款Intel产品缓冲区错误漏洞
CVE-2019-0116Intel Graphics Driver KMD模块缓冲区错误漏洞
CVE-2019-0115Intel Graphics Driver KMD模块输入验证错误漏洞
CVE-2019-0114Intel Graphics Drivers 竞争条件问题漏洞
CVE-2019-0113Intel Graphics Drivers 缓冲区错误漏洞
CVE-2019-0099Intel Server Platform Services 权限许可和访问控制问题漏洞

Showing top 20 of 65 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-11644

No comments yet


Leave a comment