9.3
CVE-2019-11351
- EPSS 3.9%
- Veröffentlicht 19.04.2019 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:20:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.9% | 0.889 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://forum.teamspeak.com/threads/139546-Release-TeamSpeak-3-Client-3-2-5
https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-004.md