Insecure Permissions in TotalAV by Protection Group
CVE-2018-7535
7.8HIGH
What is CVE-2018-7535?
The TotalAV product versions 4.1.7 through 4.6.19 exhibit an insecure permissions flaw that allows unprivileged users to modify or overwrite critical files. The permissions set to 'Everyone:F' under the %PROGRAMFILES% directory grant local users excessive control, potentially resulting in privilege escalation and complete control over the affected application.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
