vendor:
Protector Plus Antivirus Software
by:
ShineShadow Security Report
7.2
CVSS
HIGH
Local privilege escalation
264
CWE
Product Name: Protector Plus Antivirus Software
Affected Version From: Protector Plus 2009 for Windows Desktops (8.0.E03)
Affected Version To: Protector Plus Professional (9.1.001)
Patch Exists: YES
Related CWE: CVE-2009-1509
CPE: a:pspl:protector_plus_antivirus_software
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista, Windows XP, Windows Me, Windows 2000, Windows 98, Windows 2000/2003/NT server and NetWare
2009
Local privilege escalation vulnerability in Protector Plus antivirus software
Protector Plus installs the own program files with insecure permissions (Everyone - Full Control). Local attacker (unprivileged user) can replace some files (for example, executable files of Protector services) by malicious file and execute arbitary code with SYSTEM privileges.
Mitigation:
The vendor has released a patch to address this vulnerability.