CVE-2006-0230: Critical severity Symantec AntiVirus Scan Engine vulnerability
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0230?
CVE-2006-0230 is rated as a high severity vulnerability due to the potential for remote attackers to gain administrator privileges.
How do I fix CVE-2006-0230?
To fix CVE-2006-0230, upgrade Symantec Scan Engine to version 5.1.0.7 or later.
Who is affected by CVE-2006-0230?
CVE-2006-0230 affects users of Symantec Scan Engine versions 5.0.0.24 and possibly earlier versions.
What kind of attack is possible with CVE-2006-0230?
CVE-2006-0230 allows remote attackers to exploit a client-side check vulnerability to execute unauthorized actions as an administrator.
Is CVE-2006-0230 a client-side or server-side vulnerability?
CVE-2006-0230 is primarily a client-side vulnerability due to its reliance on client-side password verification affecting server security.