CVE-2020-24955: High severity superantispyware professional vulnerability
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24955?
CVE-2020-24955 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2020-24955?
To mitigate CVE-2020-24955, ensure that you are using an updated version of SUPERAntiSpyware that has addressed this vulnerability.
Who is affected by CVE-2020-24955?
CVE-2020-24955 affects users of SUPERAntiSpyware Professional X Trial version 10.0.1206 and earlier.
What type of attack does CVE-2020-24955 enable?
CVE-2020-24955 allows local unprivileged users to execute malicious DLL files with elevated privileges.
Can CVE-2020-24955 be exploited remotely?
CVE-2020-24955 requires local access to exploit, so it cannot be exploited remotely.