Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
BID:17071
Info
Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
| Bugtraq ID: | 17071 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 11 2006 12:00AM |
| Updated: | Mar 20 2006 04:44PM |
| Credit: | Ramon 'ports' Kukla is credited with the discovery of this vulnerability. |
| Vulnerable: |
free-av.de AntiVir Personal Edition Premium 0 free-av.de AntiVir Personal Edition Classic 7 |
| Not Vulnerable: |
free-av.de AntiVir Personal Edition Premium Build 128 free-av.de AntiVir Personal Edition Classic 7 Build 143 |
Discussion
Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
AntiVir Personal Edition Classic is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to launch other applications with SYSTEM privileges. This may facilitate a complete compromise of the affected computer.
AntiVir Personal Edition Classic version 7 is vulnerable; other versions may also be affected.
AntiVir Personal Edition Classic is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to launch other applications with SYSTEM privileges. This may facilitate a complete compromise of the affected computer.
AntiVir Personal Edition Classic version 7 is vulnerable; other versions may also be affected.
Exploit / POC
Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
free-av.de AntiVir Personal Edition Classic 7
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
free-av.de AntiVir Personal Edition Classic 7
-
free-av.de antivir-workstation-pers.tar.gz
Linux / FreeBSD / Solaris - AntiVir PersonalEdition Classic
http://free-av.com/personal/en/unix/antivir-workstation-pers.tar.gz -
free-av.de antivir_workstation_win7u_en_h.exe
NT/2000/XP
http://www.free-av.com/down/windows/antivir_workstation_win7u_en_h.exe
References
Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
References:
References:
- AntiVir Personal Edition Classic Web Site (free-av.de)
- AntiVir PersonalEdition Classic: Local Privilige Escalation (Ramon 'ports' Kukla
)