Vulnerability Description
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record keystrokes).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zemana | Antilogger | < 1.9.3.602 |
Related Weaknesses (CWE)
References
- https://github.com/mspaling/zemana-exclusions-poc/blob/master/zemana-whitelist-pThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148554Third Party Advisory
- https://github.com/mspaling/zemana-exclusions-poc/blob/master/zemana-whitelist-pThird Party Advisory
FAQ
What is CVE-2018-15491?
CVE-2018-15491 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2....
How severe is CVE-2018-15491?
CVE-2018-15491 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15491?
Check the references section above for vendor advisories and patch information. Affected products include: Zemana Antilogger.