CVE-2020-24955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
01/09/2020
Last modified:
21/07/2021

Description

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:superantispyware:professional_x:*:*:*:*:trial:*:*:* 10.0.1206 (excluding)