TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%, which allows local users to gain privileges by replacing executables with Trojan horse programs.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.trustport.com/en/notices/security-update-of-trustport-products | broken link vendor advisory |
http://secunia.com/advisories/36880 | broken link third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/506751/100/0/threaded | mailing list vdb entry third party advisory broken link |