Security Advisory

CVE-2019-11031

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-08-22 14:52:18
Last updated 2024-08-04 22:40:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.