Bugtraq mailing list archives
{PRL} Multiple Panda Security Products Local Privilege Escalation Vulnerability
From: Protek Research Lab <protekresearchlab () yahoo ca>
Date: Sat, 31 Oct 2009 07:24:38 -0700 (PDT)
##################################################################################### Application: Panda Global Protection 2010 Panda Internet Security 2010 Platforms: Windows XP Professional SP & windows Vista SP1 Exploitation: Local Privilege Escalation Date: 2009-10-27 Author: Francis Provencher (Protek Research Lab's) ##################################################################################### 1) Introduction 2) Technical details 3) The Code (N/A) ##################################################################################### =============== 1) Introduction =============== Panda Global Protection 2010 Enjoy total security and ensure information integrity. Enjoy optimum security and safeguard your valuable data with Panda Global Protection 2010. It protects you from viruses, spyware, rootkits, hackers, online fraud, identity theft and all other Internet threats. The anti-spam engine will keep your inbox free from junk mail while the Parental Control feature ensures your children can use the Web safely. You can also back up important files (documents, music, photos, etc.) to a CD/DVD or online and restore them in case of accidental loss or damage. (from Panda security website) 2009-10-27 Contact vendor (No response) 2009-10-29 Contact vendor (No response) 2009-10-30 Contact Vendor (Three strikes...out!) ##################################################################################### ============================ 2) Technical details ============================ Panda Global Protection 2010 Build 3.01.00 Panda Internet Security 2010 Build 15.01.00 All files under the install folder have Full control access for everyone and can be replace with malicious files. ... snip ... C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe Everyone:F ... snip ... C:\>WHOAMI.EXE FUZZYXP\test C:\>telnet 127.0.0.1 4444 C:\>WHOAMI.EXE WHOAMI.EXE AUTORITE NT\SYSTEM ##################################################################################### =========== 3) The Code =========== N\A ##################################################################################### (PRL-2009-15) __________________________________________________________________ Looking for the perfect gift? Give the gift of Flickr! http://www.flickr.com/gift/
Current thread:
- {PRL} Multiple Panda Security Products Local Privilege Escalation Vulnerability Protek Research Lab (Nov 02)
- <Possible follow-ups>
- Re: {PRL} Multiple Panda Security Products Local Privilege Escalation Vulnerability Vladimir '3APA3A' Dubrovin (Nov 02)