Vulnerabilities > CVE-2006-4927 - Privilege Escalation vulnerability in Symantec AntiVirus IOCTL Kernel

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
symantec
exploit available

Summary

The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB. Update 20061.3.0.12 has been released by the vendor for each vulnerable driver. Additionally, an update to the virus definitions (October 4, 2006 revision 9 or later) is required.

Vulnerable Configurations

Part Description Count
Application
Symantec
2

Exploit-Db

  • descriptionSymantec AntiVirus IOCTL Kernel Privilege Escalation Vulnerability (1). CVE-2006-4927 . Local exploit for windows platform
    idEDB-ID:28763
    last seen2016-02-03
    modified2006-08-26
    published2006-08-26
    reporterRuben Santamarta
    sourcehttps://www.exploit-db.com/download/28763/
    titleSymantec AntiVirus - IOCTL Kernel Privilege Escalation Vulnerability 1
  • descriptionSymantec AntiVirus IOCTL Kernel Privilege Escalation Vulnerability (2). CVE-2006-4927. Local exploit for windows platform
    idEDB-ID:28764
    last seen2016-02-03
    modified2006-08-26
    published2006-08-26
    reporterRuben Santamarta
    sourcehttps://www.exploit-db.com/download/28764/
    titleSymantec AntiVirus - IOCTL Kernel Privilege Escalation Vulnerability 2