Back

HIGH

Rapid7 InsightAppSec Local Privilege Escalation

Published Aug 19, 2019

Description

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.

Affected products

Remediation

Vendor solution

Users should update Rapid7 InsightAppSec to version 2019.07.08 or later.

Weaknesses (2)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Aug 19, 2019
Updated Sep 16, 2024
Reserved Jan 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a