CVE-2025-1368
Last modified
CVE-2025-1368 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Escanav | Escan Anti-Virus | 7.0.32 |
References
- https://github.com/dmknght/FIS_RnD/blob/main/escan_av_usb_protection_multiple_vulns.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.295972Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.295972Third Party Advisory, VDB Entry
- https://github.com/dmknght/FIS_RnD/blob/main/escan_av_usb_protection_multiple_vulns.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1368?
How severe is CVE-2025-1368?
How do I fix CVE-2025-1368?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13674BPv7 dissector crash in Wireshark 4.6.0 allows denial of ser…5.5
- CVE-2025-13675The Tiger theme for WordPress is vulnerable to Privilege Esc…9.8
- CVE-2025-13676The JustClick registration plugin for WordPress is vulnerabl…6.1
- CVE-2025-13677The Simple Download Counter plugin for WordPress is vulnerab…4.9
- CVE-2025-13678The Thai Lottery Widget plugin for WordPress is vulnerable t…6.4
- CVE-2025-13679The Tutor LMS – eLearning and online course solution plugin …6.5
- CVE-2025-13680The Tiger theme for WordPress is vulnerable to Privilege Esc…8.8
- CVE-2025-13681The BFG Tools – Extension Zipper plugin for WordPress is vul…4.9
- CVE-2025-13682The Trail Manager plugin for WordPress is vulnerable to Stor…4.4
- CVE-2025-13683Exposure of credentials in unintended requests in Devolution…6.5
- CVE-2025-13684The ARK Related Posts plugin for WordPress is vulnerable to …4.3
- CVE-2025-13685The Photo Gallery by Ays plugin for WordPress is vulnerable …4.3
Are you affected by CVE-2025-1368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
