VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/37991 | vdb entry |
http://secunia.com/advisories/27094 | third party advisory |
http://www.securityfocus.com/bid/25930 | vdb entry |
http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066313.html | vendor advisory mailing list exploit |
http://www.anti-virus.by/en/ | patch |