Symlink Attack Vulnerability in Interscan VirusWall by Trend Micro
CVE-2001-0132

Currently unrated

Key Information:

Vendor
CVE Published:
12 March 2001

What is CVE-2001-0132?

The Interscan VirusWall software, specifically versions 3.6.x and earlier, is susceptible to a symbolic link vulnerability that arises during the uninstallation process. When a local user uninstalls the product, the software improperly follows symbolic links, enabling the user to overwrite arbitrary system files through a carefully crafted symlink. This can lead to significant disruptions and allow the modification of critical files, making the system vulnerable to further exploits.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.