Filtered by vendor Totalav
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-18194 | 1 Totalav | 1 Totalav 2020 | 2024-11-21 | 6.9 MEDIUM | 7.8 HIGH |
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder. | |||||
CVE-2018-7535 | 1 Totalav | 1 Totalav | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges or obtain maximum control over the product. |