CVE-2009-4556
Last modified
CVE-2009-4556 is a vulnerability of currently unknown severity. Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Quickheal | Antivirus Plus 2009 | 10.00 | Sp1 |
| Quickheal | Total Security 2009 | 10.00 | Sp1 |
References
- http://secunia.com/advisories/37033Vendor Advisory
- http://secunia.com/advisories/37033Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4556?
How severe is CVE-2009-4556?
How do I fix CVE-2009-4556?
Are you affected by CVE-2009-4556?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
