vendor:
Max Secure Anti-Virus Plus
by:
hyp3rlinx
7.2
CVSS
HIGH
Insecure Permissions
264
CWE
Product Name: Max Secure Anti-Virus Plus
Affected Version From: 19.0.4.020
Affected Version To: 19.0.4.020
Patch Exists: NO
Related CWE: N/A
CPE: a:max_secure_software:max_secure_anti-virus_plus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2019
Max Secure Anti Virus Plus 19.0.4.020 – Insecure File Permissions
Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers or malware running at low integrity can replace a .exe or .dll file to achieve privilege escalation.
Mitigation:
Ensure the installation directory has secure permissions.