gsd-2021-26624
Vulnerability from gsd
Modified
2023-12-13 01:23
Details
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2021-26624", "description": "An local privilege escalation vulnerability due to a \"runasroot\" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to \"runasroot\" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.", "id": "GSD-2021-26624" }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2021-26624" ], "details": "An local privilege escalation vulnerability due to a \"runasroot\" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to \"runasroot\" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.", "id": "GSD-2021-26624", "modified": "2023-12-13T01:23:33.986312Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "vuln@krcert.or.kr", "ID": "CVE-2021-26624", "STATE": "PUBLIC", "TITLE": "eScan Anti-Virus Local privilege escalation Vulnerability" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "eScan Anti-Virus for Linux", "version": { "version_data": [ { "platform": "Linux", "version_affected": "\u003c=", "version_value": "7.0.31" } ] } } ] }, "vendor_name": "MicroWorld Technologies Inc." } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An local privilege escalation vulnerability due to a \"runasroot\" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to \"runasroot\" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-20 Improper Input Validation" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66596", "refsource": "MISC", "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66596" } ] }, "source": { "discovery": "UNKNOWN" } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:escanav:escan_anti-virus:*:*:*:*:*:linux:*:*", "cpe_name": [], "versionEndExcluding": "7.0.31", "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "vuln@krcert.or.kr", "ID": "CVE-2021-26624" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "An local privilege escalation vulnerability due to a \"runasroot\" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to \"runasroot\" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-20" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66596", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66596" } ] } }, "impact": { "baseMetricV2": { "acInsufInfo": false, "cvssV2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 10.0, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "HIGH", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9 } }, "lastModifiedDate": "2022-04-09T00:42Z", "publishedDate": "2022-04-01T23:15Z" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…