CVE-2019-13356: High severity totaldefense antivirus vulnerability
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13356?
CVE-2019-13356 is rated as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2019-13356?
To fix CVE-2019-13356, ensure that access controls are properly configured for the directory used by AMRT.exe.
Who is affected by CVE-2019-13356?
CVE-2019-13356 affects users of Total Defense Anti-virus version 9.0.0.773.
What can an attacker do with CVE-2019-13356?
An attacker can exploit CVE-2019-13356 to hijack the bdcore.dll file, leading to unauthorized code execution with elevated privileges.
Is there a workaround for CVE-2019-13356?
A recommended workaround for CVE-2019-13356 is to restrict permissions on the affected directory to prevent unauthorized access.