OSVDB ID: 23843

Title: AntiVir PersonalEdition Update Report Local Privilege Escalation

Info

Disclosure

Mar 09, 2006

Discovery

Mar 04, 2006

Dates

Exploit

Mar 09, 2006

Solution

Unknown

Description

AntiVir PersonalEdition for Windows contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when notepad.exe is launched with SYSTEM rights when viewing reports, which can be used to view or execute files with elevated priveleges. This flaw may lead to a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Misconfiguration
Impact: Loss of Integrity
Exploit: Exploit Public

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

AntiVir PersonalProducts GmbH

AntiVir PersonalEdition

7

References

Credit

  • Ramon 'ports' Kukla - ml2portsonline.net -


Direct URL: http://osvdb.org/23843