vendor:
OfficeScan XG
by:
John Page (aka hyp3rlinx)
4.4
CVSS
MEDIUM
Unauthorized Change Prevention Bypass
N/A
CWE
Product Name: OfficeScan XG
Affected Version From: OfficeScan XG v11.0
Affected Version To: OfficeScan XG v11.0
Patch Exists: YES
Related CWE: CVE-2018-10507
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Local
2018
Unauthorized Change Prevention Bypass
Attackers or malwarez that can access the system hosting the OfficeScan XG AV, can bypass the antivirus protection feature that prevents unauthorized changes from being made like killing protected OfficeScan XG processes such as 'PccNTMon.exe'. The exploit requires Admin permissions to exploit.
Mitigation:
Vendor released a critical patch and advisory to address the issue.