Symlink Attack Vulnerability in Interscan VirusWall by Trend Micro
CVE-2001-0132
Currently unrated
What is CVE-2001-0132?
The Interscan VirusWall software, specifically versions 3.6.x and earlier, is susceptible to a symbolic link vulnerability that arises during the uninstallation process. When a local user uninstalls the product, the software improperly follows symbolic links, enabling the user to overwrite arbitrary system files through a carefully crafted symlink. This can lead to significant disruptions and allow the modification of critical files, making the system vulnerable to further exploits.