7.8
CVSSv3

CVE-2018-17775

Published: 08/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

seqrite end point security 7.4

Exploits

# Exploit Title: Seqrite End Point Security 74 - Privilege Escalation # Date: 2018-09-13 # Exploit Author: Hashim Jawad - @ihack4falafel # Vendor Homepage: wwwseqritecom/ # Tested on: Windows 7 Enterprise SP1 (x64) # CVE: CVE-2018-17775 # Description: # Seqrite End Point Security v74 installs by default to "C:\Program Files\Seqrite\Seq ...