First published: Wed Mar 22 2006(Updated: )
avast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Antivirus | <=4.6.763 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1355 is considered a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2006-1355, upgrade to avast! Antivirus version 4.7 or later, which addresses the permission vulnerabilities.
Local users of avast! Antivirus version 4.6.763 or earlier on Windows systems are affected by CVE-2006-1355.
An attacker exploiting CVE-2006-1355 can gain elevated privileges or disable antivirus protection by modifying critical system files.
CVE-2006-1355 is not a concern for current versions of avast! Antivirus, as it has been addressed in later releases.