vendor:
Outlook Add-In
by:
PovlTekstTV
7.3
CVSS
HIGH
Local Privilege Escalation
Unknown
CWE
Product Name: Outlook Add-In
Affected Version From: Unknown
Affected Version To: 8.1.11.0
Patch Exists: YES
Related CWE: CVE-2018-19113
CPE: a:pronestor:outlook_add-in
Platforms Tested: Windows 7
2018
Pronestor Service PNHM Local Privilege Escalation
The Pronestor service PNHM before 8.1.12.0 has insecure permissions for the PronestorHealthMonitor.exe file, allowing local users to gain privileges by executing a Trojan horse PronestorHealthMonitor.exe file. The vulnerability is due to the weak file permissions set during the installation of Pronestors Outlook-Add-In, which creates the PNHM service running as SYSTEM and allows all Authenticated Users to potentially execute arbitrary code as SYSTEM on the local system.
Mitigation:
Upgrade to version 8.1.12.0 or newer.