CVE-2018-12989: Pearsonvue Console 8

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.

Affected products

  • Pearsonvue Console 8: before 2018-06-26 (fixed in 2018-06-26)
  • Pearsonvue Iqsystem 7: before 2018-06-26 (fixed in 2018-06-26)

Published 2018-08-03. Last modified 2026-06-17.