7.8
CVE-2019-6265
- EPSS 0.21%
- Veröffentlicht 25.02.2019 23:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 are affected by insecure implementations which allow remote attackers to execute arbitrary commands and escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cordaware ≫ Bestinformed SwPlatformwindows Version < 6.2.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.435 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|