Intego Antivirus for Windows 3.0.0.1 及更早版本在其优化模块中存在一个链接符号跟随漏洞,该漏洞允许本地非特权用户以 SYSTEM 权限删除任意文件夹。攻击者可以通过将被扫描的重复文件目录替换为一个指向 C:\Config.msi 的junction(符号链接),并利用 Windows Installer 的回滚机制,以 SYSTEM 权限执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Intego | Intego Antivirus | 0 ~ 3.0.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet