#VU76843 Path traversal in Antivirus Plus - CVE-2023-32176
Published: June 5, 2023
Antivirus Plus
Vipre
Description
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the SetPrivateConfig method. A local user can send a specially crafted HTTP request to escalate privileges and execute arbitrary code in the context of SYSTEM.