HIGH · 7.2

CVE-2009-4215

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replaci...

Vulnerability Description

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindows 7All versions
MicrosoftWindows VistaAll versions
MicrosoftWindows XpAll versions
PandasecurityPanda Antivirus2010
PandasecurityPanda Global Protection2010
PandasecurityPanda Internet Security2010

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-4215?

CVE-2009-4215 is a vulnerability with a CVSS score of 7.2 (HIGH). Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replaci...

How severe is CVE-2009-4215?

CVE-2009-4215 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-4215?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 7, Microsoft Windows Vista, Microsoft Windows Xp, Pandasecurity Panda Antivirus, Pandasecurity Panda Global Protection.