Remote Code Execution Vulnerability in PRTG Network Monitor by Paessler
CVE-2018-19204
8.8HIGH
What is CVE-2018-19204?
The PRTG Network Monitor prior to version 18.3.44.2054 has a vulnerability that allows remote authenticated users with read-write privileges to execute arbitrary code. The issue arises when handling user input in the HTTP Advanced Sensor's POST parameter 'proxyport_'. An attacker can craft a specific HTTP request to manipulate the 'writeresult' command-line parameter for HttpAdvancedSensor.exe, thereby gaining the ability to store and execute arbitrary data within the system's file structure. This threat presents significant risks, particularly through the unauthorized creation of executable files in sensitive directories.
