vendor:
HC10 HC.Server Service 10.14
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
Remote Invalid Pointer Write
119
CWE
Product Name: HC10 HC.Server Service 10.14
Affected Version From: 10.14
Affected Version To: 10.14
Patch Exists: YES
Related CWE: CVE-2019-12323
CPE: a:hosting_controller:hc10:10.14
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7/10
2019
Remote Invalid Pointer Write
An attacker can send a malicious request to the HC.Server service on port 8794 to cause an Invalid Pointer Write DoS. This can be used to trigger the services failure flag recovery options, which can be set to run a malicious program with SYSTEM privileges.
Mitigation:
Upgrade to HC10 10.15 or later.