CVE-2006-1381: Critical severity Trend Micro OfficeScan vulnerability
Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1381?
CVE-2006-1381 has been classified as a high severity vulnerability due to the potential for local users to gain SYSTEM privileges.
How do I fix CVE-2006-1381?
To mitigate CVE-2006-1381, ensure that the DACLs for critical files are configured securely and restrict access to authorized users only.
Which versions of Trend Micro OfficeScan are affected by CVE-2006-1381?
CVE-2006-1381 affects Trend Micro OfficeScan versions 5.5 and possibly earlier versions up to 6.5.
What are the potential risks associated with CVE-2006-1381?
The potential risks of CVE-2006-1381 include unauthorized local users gaining SYSTEM privileges, which can lead to complete control over the affected system.
Is there a workaround for CVE-2006-1381?
While the primary fix is to update the software, a temporary workaround is to monitor and limit local user permissions on affected systems.