CVE-2006-0812: High severity Visnetic Visnetic Antivirus Plug-in For Mail Server vulnerability
Published Feb 23, 2006
·Updated
The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.
Affected Software
2 affected components
Visnetic Visnetic Antivirus Plug-in For Mail Server=4.6.0.4
Visnetic Visnetic Antivirus Plug-in For Mail Server=4.6.1.1
Remediation
Patch Available
Event History
Feb 23, 2006
CVE Published
08:02 PM
Feb 24, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0812?
CVE-2006-0812 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2006-0812?
To fix CVE-2006-0812, upgrade the VisNetic AntiVirus Plug-in to version 4.6.1.2 or later.
3
Who is affected by CVE-2006-0812?
CVE-2006-0812 affects users of VisNetic AntiVirus Plug-in versions 4.6.0.4 and 4.6.1.1.
4
What type of vulnerability is CVE-2006-0812?
CVE-2006-0812 is a local privilege escalation vulnerability.
5
Can CVE-2006-0812 be exploited remotely?
No, CVE-2006-0812 requires local access to the system to be exploited.