Vulnerability Description
Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scanguard | Scanguard Antivirus | <= 2019-11-12 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.orgExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Nov/5Third Party Advisory
- https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-PermisExploitThird Party AdvisoryVDB Entry
- https://support.scanguard.com/en/kb/22/upgrades-availableProduct
- http://hyp3rlinx.altervista.orgExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Nov/5Third Party Advisory
- https://packetstormsecurity.com/files/155319/ScanGuard-Antivirus-Insecure-PermisExploitThird Party AdvisoryVDB Entry
- https://support.scanguard.com/en/kb/22/upgrades-availableProduct
FAQ
What is CVE-2019-18895?
CVE-2019-18895 is a vulnerability with a CVSS score of 7.8 (HIGH). Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
How severe is CVE-2019-18895?
CVE-2019-18895 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18895?
Check the references section above for vendor advisories and patch information. Affected products include: Scanguard Scanguard Antivirus, Microsoft Windows.