← Vulnerability feed

Vulnerability record · CVE-2019-12042 · published 23 May 2019

CVE-2019-12042: Pandasecurity panda antivirus incorrect permission assignment vulnerability

Pandasecurity · Panda Antivirus

Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.

9.8 CVSS 3.0 Critical EPSS 3.5% · top 11.3% CWE-732 · Incorrect permission assignment
9.8CVSS 3.0 base score, v2 10.0
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12042 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.8CVE-2024-7241Pandasecurity panda dome link following vulnerabilityPanda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affe…EPSS 0.34%7.8CVE-2024-7242Pandasecurity panda dome link following vulnerabilityPanda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affe…EPSS 0.34%7.8CVE-2024-7243Pandasecurity panda dome link following vulnerabilityPanda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affe…EPSS 0.34%7.8CVE-2024-7244Pandasecurity panda dome uncontrolled search path element vulnerabilityPanda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on a…EPSS 0.29%7.8CVE-2024-7245Pandasecurity panda dome incorrect permission assignment vulnerabilityPanda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala…EPSS 0.21%7.8CVE-2018-6321Pandasecurity panda global protection unquoted search path vulnerabilityUnquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges…EPSS 0.33%7.8CVE-2018-6322Pandasecurity panda global protection vulnerabilityPanda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2019-12042), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.