Insecure Permission Vulnerability in TotalAV Software
CVE-2024-31771

7.8HIGH

Key Information:

Vendor

TotalAV

Vendor
CVE Published:
14 May 2024

What is CVE-2024-31771?

An insecure permission vulnerability exists in TotalAV version 6.0.740, enabling local attackers to exploit the software's permission settings. By utilizing a specifically crafted file, attackers can escalate their privileges, potentially leading to unauthorized access to sensitive areas of the system. This vulnerability underscores the significant risks associated with improper permission controls in software applications, necessitating immediate attention to enhance security measures.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.