header-logo
Suggest Exploit
vendor:
Quick Heal Antivirus Plus 2009 for Desktop
by:
ShineShadow Security Report

Quick Heal Local Privilege Escalation Vulnerability

Quick Heal installs the own program files with insecure permissions (Everyone: Full Control). Local attacker (unprivileged user) can replace some files (for example, executable files of Quick Heal services) by malicious file and execute arbitrary code with SYSTEM privileges.

Mitigation:

Vendor released a patch.
Source

Exploit-DB raw data: