Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8372-62j2-5947

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

EPSS

Процентиль: 10%
0.00035
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

EPSS

Процентиль: 10%
0.00035
Низкий

Дефекты

CWE-269