CVE-2006-1274: High severity Avira AntiVir Personal vulnerability
Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1274?
CVE-2006-1274 is classified as a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2006-1274?
To fix CVE-2006-1274, it is recommended to update to the latest version of Avira AntiVir that addresses this privilege escalation issue.
Who is affected by CVE-2006-1274?
CVE-2006-1274 affects users of Avira AntiVir PersonalEdition Classic version 7 who have not installed security updates.
What types of attacks can exploit CVE-2006-1274?
CVE-2006-1274 can be exploited by local users to gain elevated privileges on the system.
Is there a workaround for CVE-2006-1274?
A temporary workaround for CVE-2006-1274 is to restrict access permissions for the scan report functionality until the software is updated.