PT-2004-2114 · Computer Associates · Etrust Antivirus

Published

2004-12-22

·

Updated

2021-04-09

·

CVE-2004-1149

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Computer Associates eTrust EZ Antivirus versions 7.0.0 through 7.0.4
Description: The issue allows local users to gain privileges by replacing critical programs with malicious ones due to insecure permissions (ACLs) used during the installation of its files. This can be demonstrated by replacing VetMsg.exe with a malicious program.
Recommendations: For versions 7.0.0 through 7.0.4, consider restricting access to critical programs to prevent local users from replacing them with malicious ones until a fix is available. As a temporary workaround, monitor the system for any suspicious activity related to the replacement of critical programs.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1149

Affected Products

Etrust Antivirus