MicroWorld eScan Antivirus Incorrect Default Permissions Vulnerability Allowing Privilege Escalation and Denial-of-Service on Linux

Vulnerability

A critical vulnerability exists in MicroWorld eScan Antivirus version 7.0.32 for Linux, specifically within the Installation Handler component. The issue arises from incorrect default permissions set during the installation process, which allows unprivileged users to modify files in the application's database directory. This flaw can lead to a denial-of-service condition by deleting the signatures database or to privilege escalation by overwriting engine libraries with malicious files.

Impact

Exploitation of this vulnerability can cause a denial-of-service by disrupting antivirus signature updates or allow for privilege escalation by manipulating application libraries.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.