CVE-2019-5443 describes a vulnerability in curl versions up to 7.65.1, affecting products from haxx, Microsoft, NetApp, and Oracle. A non-privileged user can place malicious code and a configuration file in a specific directory (C:/usr/local/), which curl will then automatically execute as an OpenSSL engine upon invocation. This local privilege escalation vulnerability carries a high CVSS score of 7.8, indicating that if a privileged user subsequently invokes the compromised curl, the malicious code can achieve full system compromise. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.65.1CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
12.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:* | ||
12.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:* | ||
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.