CVE-2016-3943
HIGHPanda Endpoint Administration Agent <7.50.00 - Privilege Escalation
Title source: llmDescription
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.
Exploits (1)
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/39671/
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Apr/24
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/136606/Panda-Endpoint-Administration-Agent-Privilege-Escalation.html
Scores
CVSS v3
7.8
EPSS
0.0019
EPSS Percentile
41.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-276
Status
published
Products (1)
watchguard/panda_endpoint_administration_agent
< 7.49
Published
Apr 18, 2016
Tracked Since
Feb 18, 2026