CVE-2019-3999
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
- Affected products
- Druva Insync Windows Client
- Druva Insync Client
- = 6.5.0
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 8.6% (95th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2020-02-25
CVE-2019-3999 at NVD
5 known exploits for CVE-2019-3999
Proof-of-concept code and exploit modules indexed by Sploitus
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation Exploit
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation Exploit
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
Druva inSync Windows Client 6.5.2 Privilege Escalation