CVE-2019-9565
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/03/2019
Last modified:
24/08/2020
Description
Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or upon an indirect launch via an integration such as Chrome, Firefox, Word, Outlook, etc. This occurs because the product attempts to access a share with the PLUG-INS subdomain name; an attacker may be able to use Active Directory Domain Services to register that name.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:druide:antidote:*:*:*:*:*:*:*:* | 8.0 (including) | 8.05.2287 (excluding) |
| cpe:2.3:a:druide:antidote:*:*:*:*:*:*:*:* | 9.0 (including) | 9.5.3937 (excluding) |
| cpe:2.3:a:druide:antidote:*:*:*:*:*:*:*:* | 10.0 (including) | 10.1.2147 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



