CVE Published: 01/04/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: krcert |
Vendor: MicroWorld Technologies Inc. |
Product: eScan Anti-Virus for Linux Status : PUBLISHED
CVE-2021-26624 Description
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H