PT-2025-6894 · Microworld · Microword Escan Antivirus

Dmknght

·

Published

2025-02-16

·

Updated

2025-02-17

·

CVE-2025-1364

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MicroWord eScan Antivirus version 7.0.32
Description: A critical issue has been discovered in the passPrompt function of the USB Protection Service component. This issue leads to a stack-based buffer overflow. The attack can be launched on the local host. The exploit has been publicly disclosed and may be used. The vendor was contacted about this issue but did not respond.
Recommendations: For MicroWord eScan Antivirus version 7.0.32, as a temporary workaround, consider disabling the passPrompt function of the USB Protection Service until a patch is available. Restrict access to the USB Protection Service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-00358
CVE-2025-1364

Affected Products

Microword Escan Antivirus