CVE-2019-11031: Mirasys Vms

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

Affected products

  • Mirasys Mirasys Vms: before 7.6.1 (fixed in 7.6.1); from 8.0.0, before 8.3.2 (fixed in 8.3.2)

Published 2019-08-22. Last modified 2026-06-17.