AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-5629

HIGH · CVSS 7.8 EPSS 0.90% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-07-13 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. Public exploit code or proof-of-concept references have been detected in its references. Exploitation may require the attacker to be authenticated.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-5629
Severity
HIGH
CVSS
7.8
EPSS
0.90%

Original NVD Description

Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 2.6.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)