26336Third-party advisory
http://secunia.com/advisories/26336 CVE-2007-4191
Panda AntiVirus 2008 - Local Privilege Escalation
Record summary
CVE-2007-4191 has a selected CVSS score of 6.9; EIP currently links 1 catalogued exploit.
Description
Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPanda AntiVirus 2008 - Local Privilege EscalationExploitDB exploitby tarkusNot analyzed1 file
References
112968Third-party advisory
http://securityreason.com/securityalert/2968 pandasecurity.comConfirmation
http://www.pandasecurity.com/homeusers/support/card?id=41111&idIdioma=2&ref=PAV08Dev 20070802 Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again)mailing list
http://www.securityfocus.com/archive/1/475373/100/0/threaded 20070919 RE: Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again)mailing list
http://www.securityfocus.com/archive/1/480022/100/100/threaded 20070924 RE: Re[2]: [Full-disclosure] Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again)mailing list
http://www.securityfocus.com/archive/1/480443/100/100/threaded 25186vdb entry
http://www.securityfocus.com/bid/25186 1018722vdb entry
http://www.securitytracker.com/id?1018722 ADV-2007-2784vdb entry
http://www.vupen.com/english/advisories/2007/2784 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4191 tiifp.org
https://tiifp.org/tarkus/advisories/panda030707.txt