PT-2004-2114 · Computer Associates · Etrust Antivirus

Publicado

2004-12-22

·

Atualizado

2021-04-09

·

CVE-2004-1149

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Computer Associates eTrust EZ Antivirus versions 7.0.0 through 7.0.4
Description: The issue allows local users to gain privileges by replacing critical programs with malicious ones due to insecure permissions (ACLs) used during the installation of its files. This can be demonstrated by replacing VetMsg.exe with a malicious program.
Recommendations: For versions 7.0.0 through 7.0.4, consider restricting access to critical programs to prevent local users from replacing them with malicious ones until a fix is available. As a temporary workaround, monitor the system for any suspicious activity related to the replacement of critical programs.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1149

Produtos afetados

Etrust Antivirus