2.3
CVSSv3

CVE-2025-1368

CVSSv4: 4.6 | CVSSv3: 2.3 | CVSSv2: 1.4 | VMScore: 560 | EPSS: 6.0E-5 | KEV: Not Included
Published: 17/02/2025 Updated: 18/02/2025

Vulnerability Summary

Buffer Overflow in MicroWord eScan Antivirus 7.0.32 via BasePath Argument

A vulnerability exists in MicroWorld eScan Antivirus 7.0.32 on Linux systems. The problem is in the ReadConfiguration function within the /opt/MicroWorld/etc/mwav.conf file. An attacker with local system access can manipulate the BasePath argument, causing a buffer overflow. This security issue has been publicly disclosed, and the potential for exploitation is present. The vendor was informed about the vulnerability but did not provide any response to address the problem.