CVE-2019-11660
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 7.8%
from disclosure to weapon52 days
Published on NVDSep 13
1st PoC+52d
metasploitSep 13
exploitation probability
7.8%top 6% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.
Affected products
n/a · Data Protectorpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47580cve_referencepacketstormsecurity.com/files/155076/Micro-Focus-HPE-Data-Protector-SUID-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.