vendor:
Panda Global Protection 2016 (16.1.2),Panda Antivirus Pro 2016 (16.1.2),Panda Small Business Protection (16.1.2),Panda Internet Security 2016 (16.1.2)
by:
Security-Assessment.com
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Panda Global Protection 2016 (16.1.2),Panda Antivirus Pro 2016 (16.1.2),Panda Small Business Protection (16.1.2),Panda Internet Security 2016 (16.1.2)
Affected Version From: Panda Global Protection 2016 (16.1.2)
Affected Version To: Panda Internet Security 2016 (16.1.2)
Patch Exists: YES
Related CWE: N/A
CPE: a:pandasecurity:panda_global_protection_2016
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2016
Panda Security Privilege Escalation
Multiple Panda Security products are vulnerable to local privilege escalation. As the USERS group has write permissions over the folder where the PSEvents.exe process is located, it is possible to execute malicious code as Local System. A malicious user can exploit this vulnerability by creating a malicious DLL file in that directory and name it as one of the missing DLLs. After one hour, the “PSEvents.exe” proces will be executed and the malicious DLL will be loaded.
Mitigation:
Ensure that the directory containing the “PSEvents.exe” executable does not have write permissions for the USERS group.