Escanav maintains a focused antivirus and endpoint-protection portfolio, notably the Escan Anti-Virus product line and its associated management console, which serve as critical security controls across a concentrated but prominent user base. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur across its antivirus and administrative components through weakness classes centered on input-handling defects: cross-site scripting, buffer overflows, improper input validation, command injection, and OS command injection. The concentration of critical-severity flaws in endpoint-protection software is particularly significant because such products operate with elevated privileges and sit deep in the host defense chain, making memory-safety and input-validation failures in the antivirus engine or its console a direct path to endpoint compromise. Defenders should treat Escanav advisories as high-priority for any organization deploying these products and ensure timely patching of both the antivirus engine and management infrastructure. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Escanav over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31703CRITICAL Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from par | May 17, 2023 | 9.0 | 41 | NO | YES |
CVE-2023-31702HIGH SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to per | May 17, 2023 | 7.2 | 36 | NO | YES |
CVE-2018-18388CRITICAL eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted p | Dec 20, 2018 | 9.8 | 30 | NO | NO |
CVE-2021-26624HIGH An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions r | Apr 1, 2022 | 8.8 | 29 | NO | NO |
CVE-2023-33730CRITICAL Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any a | May 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-0798HIGH A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the comp | Jan 29, 2025 | 8.1 | 27 | NO | NO |
CVE-2024-42919CRITICAL eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. | Aug 20, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-4383HIGH A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation le | Aug 16, 2023 | 7.8 | 24 | NO | NO |
CVE-2018-6203HIGH In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va | Jan 25, 2018 | 7.8 | 23 | NO | NO |
CVE-2025-1366HIGH A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The ma | Feb 17, 2025 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Escanav.
Media articles that mention a CVE ID that affects a product developed by Escanav — matched by CVE ID, not by vendor name.