First published: Mon Oct 08 2018(Updated: )
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seqrite End Point Security | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17775 has a high severity rating due to the potential for local privilege escalation.
To fix CVE-2018-17775, remove the 'Everyone: (F)' permission for the affected directory and restrict access to authorized users only.
CVE-2018-17775 specifically affects Seqrite End Point Security version 7.4.
CVE-2018-17775 allows local users to perform privilege escalation by replacing executable files with malicious software.
As of now, there is no public patch specifically mentioned for CVE-2018-17775, so manual permission adjustments are recommended.