CVE-2004-1149: High severity broadcom etrust ez antivirus vulnerability
Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1149?
CVE-2004-1149 is rated as a moderate severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2004-1149?
To fix CVE-2004-1149, ensure that the permissions on the eTrust EZ Antivirus installation directory are properly configured to restrict access to unauthorized users.
Who is affected by CVE-2004-1149?
CVE-2004-1149 affects users of Broadcom eTrust EZ Antivirus versions 7.0.0 through 7.0.4.
What kind of attack does CVE-2004-1149 enable?
CVE-2004-1149 enables local users to replace critical antivirus programs with malicious versions, leading to potential system compromise.
Is there a patch available for CVE-2004-1149?
There is no specific patch provided for CVE-2004-1149, but securing the file permissions acts as a mitigation strategy.