PT-2019-15829 · Max Secure · Max Secure Anti Virus Plus
Published
2019-11-30
·
Updated
2019-12-13
·
CVE-2019-19382
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Max Secure Anti Virus Plus version 19.0.4.020
Description
The issue concerns insecure permissions on the installation directory of the software. This allows local attackers to replace .exe or .dll files, potentially leading to privilege escalation.
Recommendations
For Max Secure Anti Virus Plus version 19.0.4.020, consider restricting access to the installation directory to prevent unauthorized modifications until a fix is available. As a temporary workaround, monitor the directory for any suspicious changes to .exe or .dll files. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Max Secure Anti Virus Plus