First published: Wed Oct 30 2019(Updated: )
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TotalDefense AntiVirus | =11.5.2.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18644 has a medium severity rating due to its ability to facilitate privileged file deletions.
To fix CVE-2019-18644, update Total Defense Anti-virus to a version later than 11.5.2.28 to mitigate the TOCTOU vulnerability.
CVE-2019-18644 involves a symbolic link attack that exploits a TOCTOU bug in the malware scan function.
CVE-2019-18644 can lead to the deletion of privileged files due to the vulnerability in Total Defense Anti-virus.
Only Total Defense Anti-virus version 11.5.2.28 is known to be vulnerable to CVE-2019-18644.