PT-2009-6377 · Panda · Panda Global Protection 2010+2
Published
2009-12-07
·
Updated
2018-10-10
·
CVE-2009-4215
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Panda Global Protection 2010
Panda Internet Security 2010
Panda Antivirus Pro 2010
Description
The issue allows local users to gain privileges by replacing executables with Trojan horse programs due to weak permissions (Everyone: Full Control) for the product files.
Recommendations
For Panda Global Protection 2010, consider restricting access to the product files to prevent unauthorized modifications until a fix is available.
For Panda Internet Security 2010, restrict write access to the product directory to minimize the risk of exploitation.
For Panda Antivirus Pro 2010, limit permissions on executable files to prevent replacement with malicious programs.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Panda Antivirus Pro 2010
Panda Global Protection 2010
Panda Internet Security 2010