Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
References
Link | Resource |
---|---|
http://hyp3rlinx.altervista.org | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2019/Nov/5 | Third Party Advisory |
https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-Permissions.html | Exploit Third Party Advisory VDB Entry |
https://support.scanguard.com/en/kb/22/upgrades-available | Product |
http://hyp3rlinx.altervista.org | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2019/Nov/5 | Third Party Advisory |
https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-Permissions.html | Exploit Third Party Advisory VDB Entry |
https://support.scanguard.com/en/kb/22/upgrades-available | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://hyp3rlinx.altervista.org - Exploit, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2019/Nov/5 - Third Party Advisory | |
References | () https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-Permissions.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://support.scanguard.com/en/kb/22/upgrades-available - Product |
Information
Published : 2019-11-14 14:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18895
Mitre link : CVE-2019-18895
CVE.ORG link : CVE-2019-18895
JSON object : View
Products Affected
scanguard
- scanguard_antivirus
microsoft
- windows
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource