Vulnerability Description
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totalav | Totalav 2020 | 4.14.31 |
References
- https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-Third Party Advisory
- https://www.youtube.com/watch?v=88qeaLq98GcExploitThird Party Advisory
- https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-Third Party Advisory
- https://www.youtube.com/watch?v=88qeaLq98GcExploitThird Party Advisory
FAQ
What is CVE-2019-18194?
CVE-2019-18194 is a vulnerability with a CVSS score of 7.8 (HIGH). TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.
How severe is CVE-2019-18194?
CVE-2019-18194 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18194?
Check the references section above for vendor advisories and patch information. Affected products include: Totalav Totalav 2020.