vendor:
Privileged Account Security Solution - Enterprise Password Vault
by:
Thomas Zuk (@Freakazoidile)
5.3
CVSS
MEDIUM
Memory Disclosure
CWE
Product Name: Privileged Account Security Solution - Enterprise Password Vault
Affected Version From: < 9.7
Affected Version To: < 10
Patch Exists: NO
Related CWE: CVE-2018-9842
CPE:
Platforms Tested: Windows 2008, Windows 2012, Windows 7, Windows 8, Windows 10
2018
CyberArk 9.7 – Memory Disclosure
There currently exists a general advisory for the CVE with a description of exploitation and how to reproduce, but without full exploit code. I have developed a working, reliable standalone Python exploit that can be successfully used by modifying only the target IP address. Attached to this email submission is the working exploit code.