PT-2019-12281 · Avira · Avira Free Security Suite
Silton Santos
·
Published
2019-08-29
·
Updated
2020-08-24
·
CVE-2019-11396
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avira Free Security Suite version 10
Description
An issue in Avira Free Security Suite allows unprivileged users to obtain SYSTEM privileges due to permissive access rights on the SoftwareUpdater folder. This can be exploited by creating pseudo-symbolic links to arbitrary files, which can be used to achieve arbitrary file creation when an update occurs. The privileged service sets access rights, offering write access to the Everyone group in any directory.
Recommendations
For Avira Free Security Suite version 10, consider restricting access to the SoftwareUpdater folder and its configuration files to prevent unprivileged users from replacing files with pseudo-symbolic links until a fix is available. As a temporary workaround, restrict write access to the Everyone group in any directory to minimize the risk of exploitation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avira Free Security Suite