vendor:
Vir.IT eXplorer Anti-Virus
by:
Parvez Anwar
7,8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Vir.IT eXplorer Anti-Virus
Affected Version From: 8.5.39
Affected Version To: 8.5.41
Patch Exists: YES
Related CWE: CVE-2017-16237
CPE: a:tgsoft:vir.it_explorer_anti-virus
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 and Windows 10 (1709)
2017
Vir.IT eXplorer Anti-Virus Arbitrary Write Privilege Escalation
Vir.IT eXplorer Anti-Virus is vulnerable to an arbitrary write privilege escalation vulnerability. This vulnerability is due to the driver VIAGLT64.SYS not validating user-supplied input before using it to write to an arbitrary memory location. An attacker can exploit this vulnerability by sending a specially crafted IOCTL request to the driver. This can allow an attacker to execute arbitrary code with elevated privileges.
Mitigation:
Upgrade to Vir.IT eXplorer Anti-Virus version 8.5.42 or later.