7.2
CVSSv2

CVE-2007-4649

Published: 31/08/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

microworld technologies escan anti-virus 9.0.722.1

microworld technologies escan internet security 9.0.722.1

microworld technologies escan virus control 9.0.722.1

Exploits

source: wwwsecurityfocuscom/bid/25493/info Multiple MicroWorld eScan products are vulnerable to a local privilege-escalation vulnerability because of insecure default file permissions Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges Successful attacks will completely compromise affected computers ...