CVE-2021-47787
7.8TotalAV · TotalAV
TotalAV 5.15.69 contains an unquoted service path vulnerability in system services running with LocalSystem privileges, which allows local attackers to gain SYSTEM-level access.
Executive summary
A vulnerability in TotalAV 5.15.69 allows local users to escalate privileges to SYSTEM by exploiting an unquoted service path configuration.
Vulnerability
The software contains an unquoted search path (CWE-428) in multiple services, including the PC Security Management Service, which run with LocalSystem privileges. An attacker with local access can place malicious executables in the path to execute arbitrary code with elevated privileges.
Business impact
Successful exploitation of this vulnerability results in full system compromise, as the attacker gains SYSTEM-level privileges. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to complete loss of confidentiality, integrity, and availability for the affected workstation or server.
Remediation
Immediate Action: Update the TotalAV software to the latest available version provided by the vendor to resolve the service path configuration.
Proactive Monitoring: Review system service configurations for unquoted paths and monitor for unauthorized executable files created within the C:\Program Files (x86)\TotalAV\ directory.
Compensating Controls: Restrict local write permissions to the application installation directory to prevent the placement of malicious binaries by unauthorized users.
Exploitation status
Public Exploit Available: Yes, a local exploit is documented on ExploitDB (EDB-ID: 50314).
Analyst recommendation
This vulnerability presents a significant risk of privilege escalation for any environment utilizing the affected version of TotalAV. Administrators must prioritize updating the software immediately. If an update cannot be applied, ensure that standard users do not possess write permissions to the installation directories of system services.
Sources
Originally found and disclosed by Andrea Intilangelo, per the CVE Program record.
- ExploitDB-50314 Exploit / PoC
- TotalAV Official Homepage
- VulnCheck Advisory: TotalAV 5.15.69 - Unquoted Service Path Third-party advisory