7.2
CVSSv2

CVE-2009-4556

Published: 04/01/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

quickheal total security 2009 10.00

quickheal antivirus plus 2009 10.00

Exploits

ShineShadow Security Report 13102009-11 TITLE Quick Heal Local Privilege Escalation Vulnerability BACKGROUND Quick Heal Technologies is leading provider of AntiVirus and Internet Security tools and is leader in Anti-Virus Technology in India A privately held company, Quick Heal Technologies Pvt Ltd (formerly known as Cat Computer Services (P ...