LiveActive security incident?Get immediate response
CVE Record

CVE-2019-19364: A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0...

A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE describes a local privilege-escalation risk in two 2019.1 installer executables. If a low-privileged user can influence the installer’s working folder before an elevated install runs, the installer may load an unintended DLL. The source bundle does not identify a vendor fix, CVSS score, or active exploitation.

Executive priority

Treat this as a hygiene and software-deployment control issue unless the affected installers are still used. Prioritize removal or replacement from shared locations because the business impact depends on an attacker timing or influencing an elevated installer run.

Technical view

CatalystProductionSuite.2019.1.exe and CatalystBrowseSuite.2019.1.exe version 1.1.0.21 reportedly attempt to load missing DLLs from the current directory. That DLL search behavior can enable DLL hijacking during installer execution, potentially escalating privileges when the installer is run with higher privileges.

Likely exposure

Exposure appears limited to environments that retain or run the named 2019.1 installer executables, especially from user-writable folders or shared deployment locations. The source bundle does not identify installed application runtime exposure beyond installer execution.

Exploitation context

The bundle does not show KEV listing or active exploitation evidence. The described abuse requires local access or write influence over the installer’s current directory and depends on the installer being executed, likely with elevated privileges.

Researcher notes

Evidence is sparse: the CVE description and gist reference support DLL hijacking in specific installer binaries, but the bundle lacks CVSS, CWE, vendor attribution, affected CPEs, patch details, and exploitation telemetry. Validate exposure by file presence and deployment workflow, not product name alone.

Mitigation direction

  • Check vendor or maintainer guidance for updated installers or advisories.
  • Do not run the affected installers from user-writable or shared folders.
  • Store software installers in admin-controlled deployment locations only.
  • Remove obsolete affected installer copies from endpoints and file shares.
  • Limit who can launch elevated software installations.

Validation and detection

  • Inventory systems and shares for the two named installer files and version 1.1.0.21.
  • Review software deployment processes for elevated execution from writable directories.
  • Confirm affected installer copies are removed or replaced where found.
  • Check endpoint management logs for historical use of these installers.
  • Track the CVE record and referenced gist for any later remediation detail.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-19364 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.