Privilege Escalation via .NET Deserialization in TinyWall Named Pipe Message Processing

Privilege Escalation via .NET Deserialization in TinyWall Named Pipe Message Processing

CVE-2019-19470 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.

Learn more about our Web Application Penetration Testing UK.