CRITICAL🇵🇱 Wersja polska

CVE-2025-0798

CVSS 9.2v4.0pub. 2025-01-29upd. 2025-10-09

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient sanitization of input data processed by the rtscanner executable file in the Quarantine Handler component. An attacker can provide specially crafted data that will be interpreted as system commands (OS command injection, CWE-77/CWE-78). The attack can be initiated remotely, although its execution requires relatively high technical complexity. Exploit details have been made public.

Impact

Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary system commands (RCE) with the privilege level of the rtscanner process, which may lead to complete system takeover, data theft, or modification.

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with the references. It should be noted that the manufacturer (MicroWorld) did not respond to the vulnerability report before its disclosure. It is recommended to monitor the manufacturer's official channels for updates, and until one is released — consider restricting network access to the system with the vulnerable software.

Who is affected

MicroWorld eScan Antivirus version 7.0.32 running on Linux systems

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Escanav Escan Anti Virus

    APP
    Escanav
    7.0.32
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2018-18388CRITICAL9.8PL ✓same product

RCE w eScan Agent (MWAGENT.EXE) poprzez port TCP 2222

CVE-2023-4383HIGH7.8same product

A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. T...

CVE-2021-26624HIGH7.8same product

An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerabili...

CVE-2025-1366MEDIUM4.8same product

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by...

CVE-2025-1367MEDIUM4.8same product

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. Th...