vendor:
TotalAV
by:
Kusol Watchara-Apanukorn
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: TotalAV
Affected Version From: 4.14.31
Affected Version To: 5.3.35
Patch Exists: YES
Related CWE: CVE-2019-18194
CPE: a:totalav:totalav:4.14.31
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2020
TotalAV 2020 4.14.31 – Privilege Escalation
TotalAV 2020 4.14.31 has quarantine flaw that allows attacker escape of privilege by using NTFS directory junction. Attacker must create NTFS directory junction to restore.
Mitigation:
Vendor released new patched (v5.3.35)