CVE-2018-19113

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2019
Last modified:
03/10/2019

Description

The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pronestor:pronestor_health_monitoring:*:*:*:*:*:*:*:* 8.1.12.0 (excluding)