CVE ID | |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Panda Software |
AFFECTED PRODUCTS |
Security for Business Communications |
VULNERABILITY DETAILS |
The specific flaw exists within the 'Panda AdminSecure Communications Agent' (Pagent.exe) which listens on tcp port 19226. The service contains a directory traversal flaw which allows for the ability to create / overwrite / delete an arbitrary file. A remote attacker can abuse this to execute remote code under the context of the SYSTEM user. |
ADDITIONAL DETAILS |
Panda Software has issued an update to correct this vulnerability. More details can be found at:
http://www.pandasecurity.com/enterprise/support/card?id=40081 |
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi aka rgod |