CVE-2019-16913

HIGH

PC Protect Antivirus 4.14.31 - Privilege Escalation via Weak Directory Permissions

Title source: llm
STIX 2.1

Description

PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the program installs a service called SecurityService that runs as LocalSystem. This allows any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a Trojan horse.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
pcprotect/antivirus 4.14.31
Published Oct 07, 2019
Tracked Since Feb 18, 2026