CVE-2000-0650 Information

Description

The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

Reference

http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0007&L=ntbugtraq&F=&S=&P=2753 http://www.osvdb.org/1458 http://www.osvdb.org/4200 http://www.securityfocus.com/bid/1458 https://exchange.xforce.ibmcloud.com/vulnerabilities/5177

Share on: