First published: Wed Dec 22 2004(Updated: )
Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom eTrust EZ Antivirus | =7.0 | |
Broadcom eTrust EZ Antivirus | =7.0.1 | |
Broadcom eTrust EZ Antivirus | =7.0.1.1 | |
Broadcom eTrust EZ Antivirus | =7.0.1.2 | |
Broadcom eTrust EZ Antivirus | =7.0.1.3 | |
Broadcom eTrust EZ Antivirus | =7.0.1.4 | |
Broadcom eTrust EZ Antivirus | =7.0.2 | |
Broadcom eTrust EZ Antivirus | =7.0.2.1 | |
Broadcom eTrust EZ Antivirus | =7.0.3 | |
Broadcom eTrust EZ Antivirus | =7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1149 is rated as a moderate severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2004-1149, ensure that the permissions on the eTrust EZ Antivirus installation directory are properly configured to restrict access to unauthorized users.
CVE-2004-1149 affects users of Broadcom eTrust EZ Antivirus versions 7.0.0 through 7.0.4.
CVE-2004-1149 enables local users to replace critical antivirus programs with malicious versions, leading to potential system compromise.
There is no specific patch provided for CVE-2004-1149, but securing the file permissions acts as a mitigation strategy.