github.com
https://github.com/secunnix/CVE-2024-27518 CVE-2024-27518
HIGH
Record summary
CVE-2024-27518 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
professional_xBrowse superantispyware / professional_xDefault status: unknown | CVE List | Through 10.0.1262 | affected |
| 10.0.1264 | affected |
Proofs of concept
1Repository PoCs
GitHubsecunnix/CVE-2024-27518Repository PoCby secunnixStars: 0Not analyzed8 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27518 superantispyware.com
https://www.superantispyware.com/ youtube.com
https://www.youtube.com/watch?v=FM5XlZPdvdo