Required CVE Record Information
Description
Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- exchange.xforce.ibmcloud.com: etrust-antivirus-insecure-permissions(18502) vdb-entryx_transferred
- idefense.com: 20041215 Computer Associates eTrust EZ Antivirus Insecure File Permission Vulnerability third-party-advisoryx_transferred
- http://crm.my-etrust.com/login.asp?username=guest&target=DOCUMENT&openparameter x_transferred