漏洞标题
MicroWord eScan 防病毒软件 USB Protection Service passPrompt栈基缓冲区溢出漏洞
漏洞描述信息
在Linux版本的MicroWord eScan Antivirus 7.0.32中发现了一个漏洞,并被评定为严重。此漏洞影响组件USB Protection Service中的passPrompt功能。该漏洞可导致基于堆栈的缓冲区溢出。可以在本地主机上发起攻击。该漏洞的利用细节已被公开,可能被利用。已提前通知厂商此漏洞披露情况,但厂商未作任何回应。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
跨界内存写
漏洞标题
MicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflow
漏洞描述信息
A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of the component USB Protection Service. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
栈缓冲区溢出