Being Stubborn Pays Off pt. 1 – CVE-2018-19204
ID: 89ee85f9-af95-578c-bb13-f047f5322373
STIX ID: report--89ee85f9-af95-578c-bb13-f047f5322373
Feed Name: SensePost Blog
Threat Score
A hands-on exploit development blog for CVE-2018-19204 in PRTG Network Monitor showing how the HttpAdvancedSensor.exe 'writeresult' parameter can be manipulated (via the proxyport_ sensor setting) to write and execute arbitrary files with SYSTEM privileges; the author documents discovery, reversing of the sensor binary, and a proof-of-concept that leverages default/authenticated access to gain local administrative control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
