packetstormsecurity.com
http://packetstormsecurity.com/files/155758/CA-Client-Automation-14.x-Privilege-Escalation.html CVE-2019-19231
HIGH
Record summary
CVE-2019-19231 has a selected CVSS score of 7.3 (high); EIP currently links 1 repository PoC.
Description
An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CA Client AutomationBrowse CA Technologies, Broadcom Company / CA Client Automation | CVE List | 14.0 | affected |
| 14.1 | affected | ||
| 14.2 | affected | ||
| 14.3 | affected |
Proofs of concept
1Repository PoCs
GitHubhessandrew/CVE-2019-19231Repository PoCby hessandrewStars: 1Not analyzed1 file
References
520200103 CA20191218-01: Security Notice for CA Client Automation Agent for Windowsmailing list
http://seclists.org/fulldisclosure/2020/Jan/5 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-19231 20191225 CA20191218-01: Security Notice for CA Client Automation Agent for Windowsmailing list
https://seclists.org/bugtraq/2019/Dec/41 techdocs.broadcom.comConfirmation
https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/CA20191218-01-security-notice-for-ca-client-automation-agent-for-windows.html