7.2
CVSSv2

CVE-2019-19470

Published: 30/12/2019 Updated: 01/01/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tinywall tinywall

Github Repositories

plaintext Here you will find some of the things that I have worked or am investigating CVE's - PoC CVE-2018-13374 CVE-2019-19470 CSharp Tools (C#) PowerEmpire UAC Bypass Masquerade PEB HackTheBox PortScan CSRF Login Brute Force (bart) PortKnocking PowerShell Invoke-InternetTest Random Python Scripts SMTP_o365