CVE-2020-36980

7.8

Segurazo · SAntivirus IC

SAntivirus IC version 10.0.21.61 is susceptible to an unquoted service path vulnerability, allowing local attackers to achieve system-level privilege escalation by injecting malicious binaries.

Executive summary

A local privilege escalation vulnerability in SAntivirus IC 10.0.21.61 allows attackers with local access to execute arbitrary code with system-level permissions.

Vulnerability

This vulnerability involves an unquoted service path in the Windows service configuration for the SAntivirusIC service. A local attacker can place a malicious executable in the path of the service, which the system will execute with SYSTEM privileges upon service restart.

Business impact

The ability for a local attacker to gain SYSTEM-level access represents a critical security failure, as it allows for complete compromise of the host machine. Given the CVSS score of 7.8, this flaw poses a significant risk to data integrity, confidentiality, and overall system availability, as the attacker could install persistent backdoors or exfiltrate sensitive information.

Remediation

Immediate Action: Since no specific patch version was provided, users should contact Segurazo support to request an update that corrects the unquoted service path. In the interim, administrators should consider removing the software if it is not business critical.

Proactive Monitoring: Monitor Windows Event Logs for unexpected service restarts or new, unauthorized binaries appearing in the C:\Program Files (x86)\Digital Communications\ directory.

Compensating Controls: Use Group Policy to restrict write permissions on the directory paths where the SAntivirus service is installed to prevent unauthorized file placement.

Exploitation status

Public Exploit Available: Yes, a functional local exploit exists as documented in the Exploit Database (EDB-ID: 49042).

Analyst recommendation

The severity of this privilege escalation flaw necessitates prompt attention. Organizations currently running SAntivirus IC 10.0.21.61 must prioritize the removal or update of this software to prevent potential system compromise by local actors.

Sources

Originally found and disclosed by Mara Ramirez, per the CVE Program record.