ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jci
Published: 2019-07-19T20:56:07.852988Z
Updated: 2024-09-17T01:40:35.591Z
Reserved: 2019-02-07T00:00:00
Link: CVE-2019-7590
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-19T21:15:11.507
Modified: 2024-11-21T04:48:23.153
Link: CVE-2019-7590
Redhat
No data.