Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24955

Опубликовано: 01 сент. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:superantispyware:professional_x:*:*:*:*:trial:*:*:*
Версия до 10.0.1206 (исключая)

EPSS

Процентиль: 10%
0.00035
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59

Связанные уязвимости

github
больше 3 лет назад

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

EPSS

Процентиль: 10%
0.00035
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59