First published: Mon Apr 18 2016(Updated: )
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Panda URL Filtering | <=4.3.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7378 is classified as a high severity vulnerability due to the privilege escalation it allows.
To fix CVE-2015-7378, update Panda Security URL Filtering to version 4.3.1.9 or later.
CVE-2015-7378 is a privilege escalation vulnerability that affects local user permissions.
CVE-2015-7378 affects users running Panda Security URL Filtering versions prior to 4.3.1.9.
CVE-2015-7378 cannot be exploited remotely as it requires local user access to modify specific files.