A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
The vulnerability consists of insufficient sanitization of input data processed by the rtscanner executable file in the Quarantine Handler component. An attacker can provide specially crafted data that will be interpreted as system commands (OS command injection, CWE-77/CWE-78). The attack can be initiated remotely, although its execution requires relatively high technical complexity. Exploit details have been made public.
Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary system commands (RCE) with the privilege level of the rtscanner process, which may lead to complete system takeover, data theft, or modification.
Security patches available from the manufacturer should be applied in accordance with the references. It should be noted that the manufacturer (MicroWorld) did not respond to the vulnerability report before its disclosure. It is recommended to monitor the manufacturer's official channels for updates, and until one is released — consider restricting network access to the system with the vulnerable software.
MicroWorld eScan Antivirus version 7.0.32 running on Linux systems
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEscanav Escan Anti Virus
APPEscanav7.0.32
Related vulnerabilities
RCE w eScan Agent (MWAGENT.EXE) poprzez port TCP 2222
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. T...
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerabili...
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by...
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. Th...