PT-2019-14863 · Pcprotect · Pcprotect Anti-Virus

Flipfl0P

·

Publicado

2019-10-07

·

Atualizado

2020-08-24

·

CVE-2019-16913

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PC Protect Antivirus version 4.14.31
Description The issue concerns weak folder permissions in the default installation directory of PC Protect Antivirus, allowing any user to modify the contents of the directory and its subfolders. Additionally, the program installs a service called SecurityService that runs as LocalSystem, which can be exploited to escalate privileges to NT AUTHORITYSYSTEM by substituting the service's binary with a malicious file.
Recommendations For PC Protect Antivirus version 4.14.31, consider restricting access to the installation directory and its subfolders to prevent unauthorized modifications. As a temporary workaround, restrict access to the SecurityService to minimize the risk of privilege escalation.

Exploit

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16913

Produtos afetados

Pcprotect Anti-Virus