exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Panda Privilege Escalation

Panda Privilege Escalation
Posted Nov 3, 2009
Authored by Francis Provencher

Panda Global Protection 2010 and Panda Internet Security 2010 suffer from a local privilege escalation vulnerability.

tags | advisory, local
SHA-256 | 64f2e9ead589a335d9a4042fdd9fb8701624f6252be4329deeab35dd37c20a00

Panda Privilege Escalation

Change Mirror Download
#####################################################################################

Application:  Panda Global Protection 2010
          Panda Internet Security 2010               

Platforms:    Windows XP Professional SP & windows Vista SP1

Exploitation: Local Privilege Escalation

Date:         2009-10-27

Author:       Francis Provencher (Protek Research Lab's)

         
#####################################################################################

1) Introduction
2) Technical details
3) The Code (N/A)


#####################################################################################

===============
1) Introduction
===============

Panda Global Protection 2010
Enjoy total security and ensure information integrity.

Enjoy optimum security and safeguard your valuable data with Panda Global Protection 2010. It protects you from viruses, spyware,

rootkits, hackers, online fraud, identity theft and all other Internet threats. The anti-spam engine will keep your inbox free from

junk mail while the Parental Control feature ensures your children can use the Web safely. You can also back up important files

(documents, music, photos, etc.) to a CD/DVD or online and restore them in case of accidental loss or damage.

(from Panda security website)


2009-10-27 Contact vendor (No response)
2009-10-29 Contact vendor (No response)
2009-10-30 Contact Vendor (Three strikes...out!)


#####################################################################################

============================
2) Technical details
============================

Panda Global Protection 2010
Build 3.01.00

Panda Internet Security 2010
Build 15.01.00

All files under the install folder have Full control access for everyone and can be replace with malicious files.

... snip ...

C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe Everyone:F

... snip ...

C:\>WHOAMI.EXE
FUZZYXP\test

C:\>telnet 127.0.0.1 4444


C:\>WHOAMI.EXE
WHOAMI.EXE
AUTORITE NT\SYSTEM





#####################################################################################

===========
3) The Code
===========

N\A


#####################################################################################
(PRL-2009-15)




__________________________________________________________________
Looking for the perfect gift? Give the gift of Flickr!

http://www.flickr.com/gift/
Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close