First published: Sat Apr 08 2006(Updated: )
The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ESET NOD32 Antivirus | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0951 is rated as a high severity vulnerability due to its potential to allow local users to execute arbitrary code.
To fix CVE-2006-0951, upgrading ESET NOD32 Antivirus to a version later than 2.5 is recommended.
The potential impacts of CVE-2006-0951 include unauthorized access and execution of code on a system running NOD32 2.5.
CVE-2006-0951 affects users of ESET NOD32 Antivirus version 2.5 on Windows operating systems.
CVE-2006-0951 is a local vulnerability since it requires access to the system to exploit.