4.6
CVSSv2

CVE-2006-4927

Published: 10/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 470
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec naveng driver

symantec navex15 driver

Exploits

// source: wwwsecurityfocuscom/bid/20360/info // Symantec AntiVirus is prone to a privilege-escalation vulnerability // Local attackers can exploit this issue to corrupt memory and execute arbitrary code with kernel-level privileges Successful exploits may facilitate a complete system compromise // This issue affects only Symantec ...
/* source: wwwsecurityfocuscom/bid/20360/info Symantec AntiVirus is prone to a privilege-escalation vulnerability Local attackers can exploit this issue to corrupt memory and execute arbitrary code with kernel-level privileges Successful exploits may facilitate a complete system compromise This issue affects only Symantec and Norton ...