Security Advisory

CVE-2019-19470

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-30 17:39:59
Last updated 2024-08-05 02:16:47
Assigner mitre
State PUBLISHED

Description

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITYSYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.