NA

CVE-2024-31771

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local malicious user to escalate privileges via a crafted file

Github Repositories

CVE-2024-31771 TotalAV Arbitrary File Write TotalAV version 60x totalav_6_0_1028-latestmp4 Timeline: 13th Feb, 2024 : Discovered 60740 vulnerable and reported to TotalAV 15th Feb, 2024: TotalAV confirmed and reproduced the issue 19th Feb, 2024: TotalAV was liaising with another vendor That vendor advised that they were working on it