CVE-2017-11319

HIGH

Perspective ICM Investigation & Case 5.1.1.16 - Authenticated Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-11319. PoCs published by Konstantinos Alexiou.

AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in Perspective ICM Investigation & Case Management software by tampering with user permission values in the Perspective.data.dll. It involves debugging the application with dnSpy to modify access levels and enable restricted features like the Administration menu.

Description

Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Konstantinos Alexiou · textwebappswindows
https://www.exploit-db.com/exploits/43210

This exploit demonstrates a privilege escalation vulnerability in Perspective ICM Investigation & Case Management software by tampering with user permission values in the Perspective.data.dll. It involves debugging the application with dnSpy to modify access levels and enable restricted features like the Administration menu.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Perspective ICM Investigation & Case Management 5.1.1.16
Auth required
Prerequisites: Authenticated access to the application · dnSpy or similar debugging tool · Local access to the installed application files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43210/

Scores

CVSS v3 8.8
EPSS 0.0556
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
resolver/perspective 5.1.1.16
Published Dec 11, 2017
Tracked Since Feb 18, 2026