Sploitus

CVE-2019-10128

No indexed exploits for CVE-2019-10128 yet

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.

Affected products
Postgresql
Postgresql
< 9.4.22, 9.5.17, 9.6.13, 10.8, 11.3
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.4% (37th percentile)
Weakness
CWE-284
NVD status
Modified
Published
2021-03-19
CVE-2019-10128 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-10128 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-10128 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.