PT-2004-2114 · Computer Associates · Etrust Antivirus
Published
2004-12-22
·
Updated
2021-04-09
·
CVE-2004-1149
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Computer Associates eTrust EZ Antivirus versions 7.0.0 through 7.0.4
Description:
The issue allows local users to gain privileges by replacing critical programs with malicious ones due to insecure permissions (ACLs) used during the installation of its files. This can be demonstrated by replacing VetMsg.exe with a malicious program.
Recommendations:
For versions 7.0.0 through 7.0.4, consider restricting access to critical programs to prevent local users from replacing them with malicious ones until a fix is available. As a temporary workaround, monitor the system for any suspicious activity related to the replacement of critical programs.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Etrust Antivirus