Vulnerability Intelligence Report
CVE-2019-5443
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.72%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗Code Injection (CWE-94)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| haxx | curl | all |
| microsoft | windows | all |
| oracle | enterprise_manager_ops_center | 12.3.3, 12.4.0 |
| oracle | http_server | 12.2.1.3.0, 12.2.1.4.0 |
| oracle | mysql_server | all |
| oracle | oss_support_tools | 20.0 |
| netapp | oncommand_insight | all |
| netapp | oncommand_unified_manager | all |
| netapp | oncommand_workflow_automation | all |
| netapp | snapcenter | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.717%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HackerOne · Bug Bounty Provider · USA |
| Reserved | 2019-01-04T00:00:00 |
| Published | 2019-07-02T18:31:23 |
| Last Updated | 2024-08-04T19:54:53 |
Community Chatter & Buzz