Computer vulnerabilities of F-Secure Anti-Virus

F-Secure Anti-Virus: executing DLL code via the installer
An attacker can create a malicious install DLL, and then put it in the current directory of F-Secure Anti-Virus, in order to execute code...
CVE-2019-11644, FSC-2019-2, VIGILANCE-VUL-29346
F-Secure: memory corruption via Windows Endpoint Protection
An attacker can generate a memory corruption via Windows Endpoint Protection of F-Secure, in order to trigger a denial of service, and possibly to run code...
CERTFR-2018-AVI-269, FSC-2018-2, VIGILANCE-VUL-26299
Antivirus: privilege escalation via Microsoft Application Verifier
An attacker can bypass restrictions via Microsoft Application Verifier of Antivirus, in order to escalate his privileges...
1116957, CVE-2017-5565, CVE-2017-5566, CVE-2017-5567, CVE-2017-6186, CVE-2017-6417, VIGILANCE-VUL-22211
F-Secure AV: Man-in-the-Middle
An attacker can act as a Man-in-the-Middle on F-Secure AV, in order to read or write data in the session...
CVE-2016-9892-ERROR, CVE-2017-6466, VIGILANCE-VUL-22075
F-Secure Anti-Virus: privilege escalation via FSGK.SYS
A local attacker can use the FSGK.SYS driver of F-Secure Anti-Virus, in order to escalate his privileges...
FSC-2015-3, VIGILANCE-VUL-17793
SSL 3.0: decrypting session, POODLE
An attacker, located as a Man-in-the-Middle, can decrypt a SSL 3.0 session, in order to obtain sensitive information...
F-Secure Anti-Virus: SQL execution via an ActiveX
An attacker can invite the victim to display a malicious web site with Internet Explorer, to load an ActiveX installed by F-Secure Anti-Virus, in order to execute SQL queries on ODBC drivers...
BID-59443, CERTA-2013-AVI-273, CVE-2013-7369, FSC-2013-1, VIGILANCE-VUL-12716
F-Secure Anti-Virus: bypassing via ELF, EXE, RAR, TAR
An attacker can create an archive or a program containing a virus, which is not detected by F-Secure Anti-Virus...
BID-52581, BID-52589, BID-52591, BID-52598, BID-52612, BID-52614, BID-52623, BID-52626, CVE-2012-1429, CVE-2012-1430, CVE-2012-1431, CVE-2012-1442, CVE-2012-1443, CVE-2012-1459, CVE-2012-1461, CVE-2012-1463, VIGILANCE-VUL-11477
F-Secure Anti-Virus: code execution via fsresh.dll
An attacker can invite the victim to display a malicious HTML document calling the F-Secure Gadget Resource Handler ActiveX, in order to execute code on his computer...
BID-49293, FSC-2011-3, VIGILANCE-VUL-10948
F-Secure AV: code execution via DLL Preload
An attacker can use a malicious DLL in order to execute code in F-Secure Anti-Virus...
ASPR #2011-01-11-1, BID-45405, FSC-2010-4, VIGILANCE-VUL-10219
