Superantispyware · Superantispyware Professional · CVE-2020-24955
**Name of the Vulnerable Software and Affected Versions**
SUPERAntiSpyware Professional X Trial version 10.0.1206
**Description**
The issue allows local privilege escalation by permitting unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction. This can be achieved by crafting a malicious `ualapi.dll` file that is detected as malware.
**Recommendations**
For version 10.0.1206, consider restricting access to the quarantine restoration feature to prevent unprivileged users from restoring malicious files into the system32 folder. As a temporary workaround, avoid using the quarantine restoration feature until a patch is available.