Vulnerabilities > CVE-2006-0812 - Unspecified vulnerability in Visnetic Antivirus Plug-In for Mail Server 4.6.0.4/4.6.1.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN visnetic
nessus
Summary
The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows |
NASL id | VISNETIC_ANTIVIRUS_PRIV_ESCALATION.NASL |
description | The version of VisNetic AntiVirus Plug-in for MailServer installed on the remote host does not drop its privileges before invoking other programs. An attacker with local access can exploit this flaw to execute arbitrary programs on the affected host with LOCAL SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20993 |
published | 2006-03-03 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20993 |
title | Visnetic AntiVirus Plug-in for MailServer Local Privilege Escalation |
code |
|
References
- http://secunia.com/advisories/16583
- http://secunia.com/advisories/16583
- http://secunia.com/secunia_research/2005-65/advisory/
- http://secunia.com/secunia_research/2005-65/advisory/
- http://securitytracker.com/id?1015670
- http://securitytracker.com/id?1015670
- http://www.securityfocus.com/archive/1/425890/100/0/threaded
- http://www.securityfocus.com/archive/1/425890/100/0/threaded
- http://www.securityfocus.com/bid/16788
- http://www.securityfocus.com/bid/16788
- http://www.vupen.com/english/advisories/2006/0701
- http://www.vupen.com/english/advisories/2006/0701
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24928