CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-1367: MicroWord eScan Antivirus USB Password sprintf buffer overflow

4.8 CVSS

Description

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way. Es wurde eine Schwachstelle in MicroWord eScan Antivirus 7.0.32 für Linux ausgemacht. Sie wurde als kritisch eingestuft. Hiervon betroffen ist die Funktion sprintf der Komponente USB Password Handler. Mittels dem Manipulieren mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff muss lokal erfolgen.

Classification

CVE ID: CVE-2025-1367

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products

Vendor: MicroWord

Product: eScan Antivirus

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.32% (scored less or equal to compared to others)

EPSS Date: 2025-03-18 (when was this score calculated)

References

https://vuldb.com/?id.295971
https://vuldb.com/?ctiid.295971
https://github.com/dmknght/FIS_RnD/blob/main/escan_av_usb_protection_multiple_vulns.md

Timeline