CVE-2020-24955

Publication date

2020-09-01 21:40:58

Family

mitre

State

PUBLISHED

Description

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.