7.2
CVE-2007-4649
- EPSS 0.89%
- Veröffentlicht 31.08.2007 23:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:30
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microworld Technologies ≫ Escan Anti-virus Version9.0.722.1
Microworld Technologies ≫ Escan Internet Security Version9.0.722.1
Microworld Technologies ≫ Escan Virus Control Version9.0.722.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.545 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065509.html
http://secunia.com/advisories/26581
http://securityreason.com/securityalert/3085
http://www.securityfocus.com/bid/25493
https://exchange.xforce.ibmcloud.com/vulnerabilities/36367