Release date:
Updated on:
Affected Systems:
F-Secure BlackList 2.2.1092
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49159
F-Secure BlackLight is used to detect hidden files, folders, processes, and other programs. It can also be renamed to remove malware.
F-Secure has the local permission Escalation Vulnerability in implementation. Local attackers can replace the affected files with executable files, execute arbitrary code with system-level permissions, and completely control the local computer.
This vulnerability is caused by incorrect permission for the C tag (change/write) of the Everyone group in the fsbl.exe binary file.
<* Source: Gjoko Krstic (liquidworm@gmail.com)
Link: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5038.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
F-Secure
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.f-secure.com/