← Back to browse · API

CVE-2019-19896

Severity
CRITICAL
CVSS
9.9
EPSS
0.03035
Risk score
40.66
CISA KEV
No
PoC
No
Published
2020-01-23
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-9489, GHSA-G2J7-JQW5-568R
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-9489

Description

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.

References