CVE-2006-1355: High severity alwil avast antivirus vulnerability
avast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1355?
CVE-2006-1355 is considered a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2006-1355?
To fix CVE-2006-1355, upgrade to avast! Antivirus version 4.7 or later, which addresses the permission vulnerabilities.
Who is affected by CVE-2006-1355?
Local users of avast! Antivirus version 4.6.763 or earlier on Windows systems are affected by CVE-2006-1355.
What can an attacker do with CVE-2006-1355?
An attacker exploiting CVE-2006-1355 can gain elevated privileges or disable antivirus protection by modifying critical system files.
Is CVE-2006-1355 still a concern for current software?
CVE-2006-1355 is not a concern for current versions of avast! Antivirus, as it has been addressed in later releases.