← Vulnerability feed

Vulnerability record · CVE-2009-4215 · published 7 December 2009

CVE-2009-4215: Pandasecurity panda antivirus permissions and access controls vulnerability

Pandasecurity · Panda Antivirus

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.

7.2 CVSS 2.0 High EPSS 0.37% · top 71.9% CWE-264 · Permissions and access controls
7.2CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-4215 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.8CVE-2018-6321Pandasecurity panda global protection unquoted search path vulnerabilityUnquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges…EPSS 0.33%7.8CVE-2018-6322Pandasecurity panda global protection vulnerabilityPanda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\…EPSS 0.29%7.5CVE-2017-17683Pandasecurity panda global protection memory buffer overflow vulnerabilityPanda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request.EPSS 1.1%7.5CVE-2017-17684Pandasecurity panda global protection memory buffer overflow vulnerabilityPanda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request.EPSS 1.1%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2009-4215), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.