CVE-2024-31771

HIGH

TotalAV <6.0.740 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-31771. PoCs published by restdone.

AI-analyzed exploit summary This repository provides a detailed technical writeup for CVE-2024-31771, an arbitrary file write vulnerability in TotalAV 6.0.x. It describes the exploitation steps involving DLL quarantine, junction creation, and privilege escalation via Windows Update service.

Description

Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file

Exploits (1)

nomisec WRITEUP
by restdone · poc
https://github.com/restdone/CVE-2024-31771

This repository provides a detailed technical writeup for CVE-2024-31771, an arbitrary file write vulnerability in TotalAV 6.0.x. It describes the exploitation steps involving DLL quarantine, junction creation, and privilege escalation via Windows Update service.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: TotalAV version 6.0.x
No auth needed
Prerequisites: Access to a vulnerable TotalAV installation · Ability to create junctions and restore quarantined files
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/restdone/CVE-2024-31771

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 26.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
totalav/totalav 6.0.740
Published May 14, 2024
Tracked Since Feb 18, 2026