PT-2025-4057 · Microworld · Escan Antivirus

Dmknght

·

Published

2025-01-29

·

Updated

2025-10-09

·

CVE-2025-0798

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MicroWorld eScan Antivirus version 7.0.32
Description This issue affects the Quarantine Handler component, specifically the rtscanner file, leading to os command injection. The attack may be initiated remotely, with a rather high complexity of attack. The exploitation is known to be difficult. The vendor was contacted about this disclosure but did not respond.
Recommendations MicroWorld eScan Antivirus version 7.0.32: Update the Quarantine Handler component to prevent os command injection, or apply a patch if provided by the vendor to fix the issue in the rtscanner file. As a temporary workaround, consider disabling the rtscanner component until a patch is available.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-0798

Affected Products

Escan Antivirus