CVE-2019-19315

HIGH

Nalpeiron Licensing Service <7.3.4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nlsX86ccMailslot mailslot.

Exploits (1)

nomisec WORKING POC 4 stars
by monoxgas · poc
https://github.com/monoxgas/mailorder

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_misc
https://github.com/monoxgas/mailorder

Scores

CVSS v3 7.1
EPSS 0.0221
EPSS Percentile 84.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-732
Status published
Products (1)
nalpeiron/licensing_service 7.3.4.0
Published Dec 17, 2019
Tracked Since Feb 18, 2026