CVE-2007-5254: High severity VirusBlokAda Vba32 AntiVirus vulnerability
Published Oct 6, 2007
·Updated
VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.
Affected Software
1 affected component
VirusBlokAda Vba32 AntiVirus=3.12.2
Remediation
Patch Available
Event History
Oct 6, 2007
CVE Published
05:17 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5254?
CVE-2007-5254 has a medium severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2007-5254?
To fix CVE-2007-5254, change the permissions of the installation directory to restrict write access for unauthorized users.
3
What type of vulnerability is CVE-2007-5254?
CVE-2007-5254 is a local privilege escalation vulnerability caused by weak directory permissions.
4
Who is affected by CVE-2007-5254?
CVE-2007-5254 affects users of VirusBlokAda VBA32 AntiVirus version 3.12.2.
5
What can attackers do with CVE-2007-5254?
Attackers can replace application programs in the installation directory to execute malicious code with elevated privileges.