Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://hyp3rlinx.altervista.org | third party advisory exploit |
https://support.scanguard.com/en/kb/22/upgrades-available | product |
https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-Permissions.html | exploit vdb entry third party advisory |
http://seclists.org/fulldisclosure/2019/Nov/5 | third party advisory mailing list |