Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26624

Опубликовано: 01 апр. 2022
Источник: nvd
CVSS3: 7.8
CVSS3: 8.8
CVSS2: 10
EPSS Низкий

Описание

An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:escanav:escan_anti-virus:*:*:*:*:*:linux:*:*
Версия до 7.0.31 (исключая)

EPSS

Процентиль: 84%
0.02082
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.

EPSS

Процентиль: 84%
0.02082
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-20