PT-2019-15829 · Max Secure · Max Secure Anti Virus Plus
Publicado
2019-11-30
·
Atualizado
2019-12-13
·
CVE-2019-19382
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Max Secure Anti Virus Plus version 19.0.4.020
Description
The issue concerns insecure permissions on the installation directory of the software. This allows local attackers to replace .exe or .dll files, potentially leading to privilege escalation.
Recommendations
For Max Secure Anti Virus Plus version 19.0.4.020, consider restricting access to the installation directory to prevent unauthorized modifications until a fix is available. As a temporary workaround, monitor the directory for any suspicious changes to .exe or .dll files. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Max Secure Anti Virus Plus