First published: Fri Mar 24 2006(Updated: )
Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan Corporate Edition | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1381 has been classified as a high severity vulnerability due to the potential for local users to gain SYSTEM privileges.
To mitigate CVE-2006-1381, ensure that the DACLs for critical files are configured securely and restrict access to authorized users only.
CVE-2006-1381 affects Trend Micro OfficeScan versions 5.5 and possibly earlier versions up to 6.5.
The potential risks of CVE-2006-1381 include unauthorized local users gaining SYSTEM privileges, which can lead to complete control over the affected system.
While the primary fix is to update the software, a temporary workaround is to monitor and limit local user permissions on affected systems.