CVE-2009-4215Panda Antivirus vulnerability

CWE-2643 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.0%
top 87.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 2

Description

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pwcw-cc5w-f5wp: Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whic2022-05-02
CVEList
CVE-2009-4215: Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whic2009-12-07
CVE-2009-4215 — Panda Antivirus vulnerability | cvebase