vendor:
End Point Security
by:
Hashim Jawad
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: End Point Security
Affected Version From: 7.4
Affected Version To: 7.4
Patch Exists: NO
Related CWE: CVE-2018-17775
CPE: a:seqrite:end_point_security:7.4
Platforms Tested: Windows 7 Enterprise SP1 (x64)
2018
Seqrite End Point Security 7.4 โ Privilege Escalation
Seqrite End Point Security v7.4 installs with weak folder permissions, allowing any user to gain full permission to the program directory. Additionally, the program installs services that run as 'LocalSystem' without the 'Self Protection' feature enabled, allowing a non-privileged user to elevate privileges to 'NT AUTHORITYSYSTEM'.
Mitigation:
Apply proper folder permissions and enable the 'Self Protection' feature.