CVE-2018-19234: Comparex Miss Marple

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation.

Affected products

  • Comparex Miss Marple: before 2.0 (fixed in 2.0)

Published 2018-12-20. Last modified 2026-06-17.