Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
References
Link | Resource |
---|---|
https://blog.mirch.io/2019/12/18/signal-desktop-windows-lpe/ | Exploit Patch Third Party Advisory |
https://github.com/signalapp/Signal-Desktop/commit/2da39cca673cc11be3c6d70d4fb95889f9ab6688 | Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-12-24T14:07:20
Updated: 2019-12-24T14:07:20
Reserved: 2019-12-24T00:00:00
Link: CVE-2019-19954
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-12-24T15:15:11.473
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-19954
JSON object: View
Redhat Information
No data.
CWE