REVE Antivirus for Linux Incorrect Default Permissions Vulnerability
Vulnerability
A critical vulnerability exists in REVE Antivirus version 1.0.0.0 for Linux, specifically within the file '/usr/local/reveantivirus/tmp/reveinstall'. The issue arises from insecure default file permissions that allow unprivileged users to modify system service units in '/etc/init.d/'. This manipulation can lead to privilege escalation, as overwritten files can execute malicious code as root after a system reboot.
Impact
Exploiting this vulnerability could allow an unprivileged user to gain root access by overwriting writable system service units with malicious code that is executed after a reboot.
Reproduction
To reproduce this vulnerability, first overwrite a writable service unit in '/etc/init.d/' with a payload, such as a command to create a file in the '/tmp' directory. After injecting the payload, reboot the system. The injected command will be executed upon startup, demonstrating the privilege escalation potential.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
