CVE-2019-3999
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 8.6%
from disclosure to weapon64 days
Published on NVDFeb 25
1st PoC+64d
metasploitFeb 25
exploitation probability
8.6%top 5% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
Affected products
n/a · Druva inSync Windows Clientpublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/48400cve_referencepacketstormsecurity.com/files/157493/Druva-inSync-Windows-Client-6.5.2-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/157680/Druva-inSync-inSyncCPHwnet64.exe-RPC-Type-5-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.