ResearchVulnerability in Webroot Antivirus

Vulnerability in Webroot Antivirus

Webroot Antivirus is an antivirus software. The vulnerability existed in both the end user product and the enterprise product.

CVE-2023-7241 - Local privilege escalation vulnerability in Webroot Antivirus
The fixed vulnerability allowed an attacker to escalate his privileges to SYSTEM on a system that the attacker already had access to.

This was possible by using COM-Hijacking to execute code in the context of a trusted front-end process. The trust between the front end and the back end was then abused for an arbitrary file delete, which allowed the execution of code as SYSTEM.

We want to thank OpenText for their exemplary reaction to the vulnerability report.

CVSS-Score
7.8 (CVSS v3) - https://nvd.nist.gov/vuln/detail/CVE-2023-7241

Affected Versions
Webroot Antivirus 8.0.1X- 9.0.35.12

Fixed Version: 
9.0.35.17

References:

answers.webroot.com/Webroot/ukp.aspx

Credits: Kolja Grassmann (cirosec GmbH) and Alain Rödel (Neodyme)

Timeline
December 4, 2023: Manufacturer was contacted and informed about the vulnerability
December 5, 2023: Initial response from manufacturer
February 2, 2024: Manufacturer informed us that there is a fix available for testing
February 26, 2024: Confirm to the manufacturer that the exploit was no longer possible
May 1, 2024: Manufacturer released advisory