CVE-2007-4649
published 2007-08-31CVE-2007-4649: MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.89%
54.7th percentile
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microworld_technologies | escan_anti-virus | — | — |
| microworld_technologies | escan_internet_security | — | — |
| microworld_technologies | escan_virus_control | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065509.htmlhttp://secunia.com/advisories/26581http://securityreason.com/securityalert/3085http://www.securityfocus.com/bid/25493https://exchange.xforce.ibmcloud.com/vulnerabilities/36367http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065509.htmlhttp://secunia.com/advisories/26581http://securityreason.com/securityalert/3085http://www.securityfocus.com/bid/25493https://exchange.xforce.ibmcloud.com/vulnerabilities/36367
2007-08-31
Published