CVE-2006-1380: High severity trendmicro interscan messaging security suite vulnerability
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1380?
CVE-2006-1380 is rated as critical due to its potential to allow local users to gain SYSTEM privileges.
How do I fix CVE-2006-1380?
To fix CVE-2006-1380, update to Trend Micro InterScan Messaging Security Suite version 5.7.0.1121 or later.
Which versions of Trend Micro InterScan Messaging Security Suite are affected by CVE-2006-1380?
CVE-2006-1380 affects versions prior to 5.7.0.1121, specifically build 1183 and possibly earlier builds of version 5.5.
What is the impact of CVE-2006-1380?
The impact of CVE-2006-1380 is that local users can modify critical system files, potentially leading to unauthorized system access.
Is there a patch available for CVE-2006-1380?
Yes, a patch is available through the official update for Trend Micro InterScan Messaging Security Suite.