Описание
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:totaldefense:anti-virus:11.5.2.28:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00266
Низкий
5.9 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-367
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.
EPSS
Процентиль: 50%
0.00266
Низкий
5.9 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-367