PT-2019-12281 · Avira · Avira Free Security Suite
Silton Santos
·
Publicado
2019-08-29
·
Atualizado
2020-08-24
·
CVE-2019-11396
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avira Free Security Suite version 10
Description
An issue in Avira Free Security Suite allows unprivileged users to obtain SYSTEM privileges due to permissive access rights on the SoftwareUpdater folder. This can be exploited by creating pseudo-symbolic links to arbitrary files, which can be used to achieve arbitrary file creation when an update occurs. The privileged service sets access rights, offering write access to the Everyone group in any directory.
Recommendations
For Avira Free Security Suite version 10, consider restricting access to the SoftwareUpdater folder and its configuration files to prevent unprivileged users from replacing files with pseudo-symbolic links until a fix is available. As a temporary workaround, restrict write access to the Everyone group in any directory to minimize the risk of exploitation.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Avira Free Security Suite