CVEs Blog | G5 Cyber Security

CVE-2020-24955 – SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local pri

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24955

Reference (s):

Exit mobile version