vendor:
ScanGuard Antivirus
by:
hyp3rlinx
7.8
CVSS
HIGH
Insecure Permissions
CWE
Product Name: ScanGuard Antivirus
Affected Version From: Latest
Affected Version To: Latest
Patch Exists: NO
Related CWE: CVE-2019-18895
CPE:
Platforms Tested: Windows
2019
ScanGuard Antivirus 2020 – Insecure Folder Permissions
Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file. The product sets weak access control restrictions, as permissions are set to Full Control for Everyone group. This can allow low integrity malware the ability to replace ScanGuard executables.
Mitigation:
Apply the necessary security updates or patches provided by the vendor.