vendor:
PCProtect
by:
Hashim Jawad
7.5
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: PCProtect
Affected Version From: 4.8.35
Affected Version To: 4.8.35
Patch Exists: NO
Related CWE:
CPE: a:pcprotect:pcprotect:4.8.35
Platforms Tested: Windows
2018
PCProtect 4.8.35 โ Privilege Escalation
PCProtect Anti-Virus v4.8.35 installs with weak folder permissions and a service that can be exploited to escalate privileges to NT AUTHORITYSYSTEM.
Mitigation:
The vendor should fix the folder permissions and ensure the service is running under a more restricted account.