PT-2025-4056 · Microworld · Escan Antivirus

CVE-2025-0797

·

Publicado

2025-01-29

·

Atualizado

2025-10-09

CVSS v4.0

4.8

Média

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MicroWorld eScan Antivirus version 7.0.32
Description The issue affects the Quarantine Handler component, specifically the file /var/Microworld/, leading to incorrect default permissions. This can be exploited locally, and the exploit has been disclosed. The vendor was contacted about the disclosure but did not respond. The attack needs to be approached locally.
Recommendations MicroWorld eScan Antivirus version 7.0.32: Update the permissions of the /var/Microworld/ file to the correct default settings to prevent exploitation.

Exploit

Correção

LPE

Incorrect Privilege Assignment

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-0797

Produtos afetados

Escan Antivirus