7.8
CVSSv3

CVE-2018-7535

Published: 13/07/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges or obtain maximum control over the product.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totalav totalav

Exploits

A vulnerability allows local attackers to escalate privilege on TotalAV versions 417 through 4619 because of weak "C:\Program Files\TotalAV" permissions The specific flaw exists within the access control that is set and modified during the installation of the product The product sets weak access control restrictions An attacker can leverage ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Total AV 417 ~ 4 619 - Insecure Permissions <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: filipe &l ...