Insecure Permissions in Netwrix Auditor Logs by Netwrix
CVE-2019-14969
7.8HIGH
What is CVE-2019-14969?
Netwrix Auditor versions prior to 9.8 exhibit a significant vulnerability due to insecure permissions on log directories, specifically %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and its sub-folders. The associated service, Netwrix.ADA.StorageAuditService, fails to apply proper impersonation techniques. This oversight allows low-privileged users to potentially exploit the permissions set on the logs, facilitating attacks such as DLL hijacking and binary planting. Consequently, an attacker could execute arbitrary code with elevated privileges, mimicking the NT AUTHORITY\SYSTEM profile by leveraging symbolic links.