CVE-2019-13357: High severity totaldefense antivirus vulnerability
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13357?
CVE-2019-13357 is considered to have a high severity due to its potential to allow code execution at the SYSTEM level.
How do I fix CVE-2019-13357?
To mitigate CVE-2019-13357, update Total Defense Anti-virus to a version later than 9.0.0.773.
What type of attack does CVE-2019-13357 enable?
CVE-2019-13357 enables local attackers to perform DLL hijacking, leading to arbitrary code execution.
What component is involved in CVE-2019-13357?
The vulnerability involves the caschelp.exe component of Total Defense Anti-virus.
Is my system at risk if I am using Total Defense Anti-virus 9.0.0.773?
Yes, systems running Total Defense Anti-virus 9.0.0.773 are at risk for exploitation due to CVE-2019-13357.