CVE-2024-13990 Details
Description
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payloads for legitimate ones. The eScan AV client accepted these substituted packages and executed or loaded their components (including sideloaded DLLs and Java/installer payloads), enabling remote code execution on affected systems. MicroWorld eScan confirmed remediation of the update mechanism on 2023-07-31 but versioning details are unavailable. NOTE: MicroWorld eScan disputes the characterization in third-party reports, stating the issue relates to 2018–2019 and that controls were implemented then.
A vulnerability in the update mechanism of MicroWorld eScan Antivirus has been identified, allowing for man-in-the-middle (MitM) attacks. The issue arises because update packages were delivered over HTTP without proper cryptographic verification, enabling attackers to intercept and replace legitimate update payloads with malicious ones. This vulnerability has been exploited to distribute GuptiMiner malware, which installs backdoors and cryptocurrency miners on infected systems. eScan has confirmed that the vulnerability was addressed on July 31, 2023, but new infections continue to be observed, likely from users with outdated versions of the software.
Users are advised to update to the latest version of eScan Antivirus, which is not vulnerable to this issue. For those who have been infected with GuptiMiner, running a comprehensive scan with an updated antivirus program should help detect and remove the malware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 19, 2025CISA-ADP
Assessed Sep 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MicroWorld eScan | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2025 | New CVE Received | [email protected] |
Volerion