Insecure DLL loading in Cisco AMP for Endpoints - CVE-2021-1386
Published: April 7, 2021 / Updated: May 3, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can place a malicious .dll file in certain location on the system and execute arbitrary code with SYSTEM privileges.
Note, the vulnerability affects Windows installations only.
Affected software
ClamAV
Cisco Immunet
clamav (Alpine package)
How to mitigate CVE-2021-1386
ClamAV - update to 0.103.2
clamav (Alpine package) - update to 0.103.2-r0
Cisco Immunet - update to 7.4.0