CVE-2019-8351: Heimdalsecurity Thor

Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

  • Heimdalsecurity Thor: version 2.5.170 only; version 2.5.171 only; version 2.5.172 only

Published 2019-03-21. Last modified 2026-06-17.