SUPERAntiSpyware Professional X Trial < 10.0.1206 Local Privilege Escalation

Posted by b1nary on Aug 29

# Vulnerability Description
SUPERAntiSpyware Professional X Trial versions prior to 10.0.1206 are
vulnerable to local privilege escalation because it allows unprivileged
users to restore quarantined files to a privileged location through a NTFS
directory junction.

# Home Page

# Author: b1nary

# Proof of Concept

1. Place a dll payload in an empty folder
2. Scan the payload with the SUPERAntiSpyware…

Original Source