CVE-2018-19113
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2019
Last modified:
17/06/2026
Description
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pronestor:pronestor_health_monitoring:*:*:*:*:*:*:*:* | 8.1.12.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/153275/Pronestor-Health-Monitoring-Privilege-Escalation.html
- https://gist.github.com/povlteksttv/8f990e11576e1e90e8fb61acf8646d28
- https://www.pronestor.com
- http://packetstormsecurity.com/files/153275/Pronestor-Health-Monitoring-Privilege-Escalation.html
- https://gist.github.com/povlteksttv/8f990e11576e1e90e8fb61acf8646d28
- https://www.pronestor.com



