First published: Sat Oct 06 2007(Updated: )
VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirusBlokAda VBA32 | =3.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5254 has a medium severity rating due to its potential for local privilege escalation.
To fix CVE-2007-5254, change the permissions of the installation directory to restrict write access for unauthorized users.
CVE-2007-5254 is a local privilege escalation vulnerability caused by weak directory permissions.
CVE-2007-5254 affects users of VirusBlokAda VBA32 AntiVirus version 3.12.2.
Attackers can replace application programs in the installation directory to execute malicious code with elevated privileges.