Insecure Permissions in Netwrix Auditor Logs by Netwrix
CVE-2019-14969
7.8HIGH
What is CVE-2019-14969?
Netwrix Auditor versions prior to 9.8 exhibit a significant vulnerability due to insecure permissions on log directories, specifically %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and its sub-folders. The associated service, Netwrix.ADA.StorageAuditService, fails to apply proper impersonation techniques. This oversight allows low-privileged users to potentially exploit the permissions set on the logs, facilitating attacks such as DLL hijacking and binary planting. Consequently, an attacker could execute arbitrary code with elevated privileges, mimicking the NT AUTHORITY\SYSTEM profile by leveraging symbolic links.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved