CVE-2019-12042
moderate-risk
Published 2019-05-23
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.
Do I need to act?
-
0.67% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (6)
Panda Antivirus
Panda Antivirus Pro
Panda Dome
Panda Global Protection
Panda Gold Protection
Panda Internet Security
Affected Vendors
References (6)
Vendor Advisory
https://www.pandasecurity.com/usa/support/card?id=100063
Vendor Advisory
https://www.pandasecurity.com/usa/support/card?id=100063
47
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
13/34 · Low