Show filters
595 Total Results
Displaying 101-110 of 595
Sort by:
Attacker Value
Unknown

CVE-2021-4199

Disclosure Date: February 05, 2022 (last updated February 23, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.
Attacker Value
Unknown

CVE-2021-37852

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Attacker Value
Unknown

CVE-2021-33828

Disclosure Date: January 15, 2022 (last updated February 23, 2025)
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
Attacker Value
Unknown

CVE-2021-33827

Disclosure Date: January 15, 2022 (last updated February 23, 2025)
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
Attacker Value
Unknown

CVE-2021-34998

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named pipes. The issue results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-14208.
Attacker Value
Unknown

CVE-2021-45339

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.
Attacker Value
Unknown

CVE-2021-45338

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3) reset security.
Attacker Value
Unknown

CVE-2021-45337

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wsc_proxy.exe which could lead to acquire antimalware (AM-PPL) protection.
Attacker Value
Unknown

CVE-2021-45336

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfaces which could lead to exit the sandbox and acquire SYSTEM privileges.
Attacker Value
Unknown

CVE-2021-45335

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.