Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM privileges. Arbitrary file creation can be achieved by abusing the SwuConfig.json file creation: an unprivileged user can replace these files by pseudo-symbolic links to arbitrary files. When an update occurs, a privileged service creates a file and sets its access rights, offering write access to the Everyone group in any directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Avira Operations Free Security Suite Software Updater 后置链接漏洞
Vulnerability Description
Avira Operations Free Security Suite是Avira Operations公司的一套计算机安全解决方案套件。该产品包括防病毒、VPN(虚拟专用网络)和密码管理等功能。Software Updater是其中的一个软件更新程序。 Avira Operations Free Security Suite 2019中的Software Updater 2.0.6.13175版本中存在后置链接漏洞。该漏洞源于网络系统或产品未正确过滤表示非预期资源的链接或者快捷方式的文件名。攻击者可利
CVSS Information
N/A
Vulnerability Type
N/A