CVE-2025-1370: MicroWorld eScan Antivirus Autoscan USB epsdaemon sprintf os command injection

Medium (4.8)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Eine kritische Schwachstelle wurde in MicroWorld eScan Antivirus 7.0.32 für Linux entdeckt. Es geht hierbei um die Funktion sprintf der Datei epsdaemon der Komponente Autoscan USB. Durch Beeinflussen mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Der Angriff muss lokal passieren. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-1370

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products

Vendor: MicroWorld

Product: eScan Antivirus

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 0.19289 (how common is this exploit)

EPSS Date: 2025-03-15 (when was this score calculated)

Timeline