First published: Mon Oct 23 2006(Updated: )
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Antivirus with Backup | =9.0.2.1000 | |
Symantec Norton Antivirus with Backup | =8.01.460 | |
Symantec Client Security | =2.0.1_build_9.0.1.1000-mr1 | |
Symantec Client Security | =2.0.3_build_9.0.3.1000-mr3 | |
Symantec Norton Antivirus with Backup | =9.0.2 | |
Symantec Client Security | =1.1.1_build_393 | |
Symantec Norton Antivirus with Backup | =8.01.437 | |
Symantec Client Security | =1.1.1_mr1_build_8.1.1.314a | |
Symantec Norton Antivirus with Backup | =8.1.1_build393 | |
Symantec Norton Antivirus with Backup | =8.1.1.323 | |
Symantec Norton Antivirus with Backup | =8.01.457 | |
Symantec Norton Antivirus with Backup | =8.1.1_build8.1.1.314a | |
Symantec Client Security | =1.1.1 | |
Symantec Norton Antivirus with Backup | =9.0.1.1.1000 | |
Symantec Norton Antivirus with Backup | =8.1.0.825a | |
Symantec Norton Antivirus with Backup | =8.01.446 | |
Symantec Norton Antivirus with Backup | =8.01.464 | |
Symantec Norton Antivirus with Backup | =9.0.1 | |
Symantec Norton Antivirus with Backup | =9.0.1.1000 | |
Symantec Client Security | =1.1 | |
Symantec Norton Antivirus with Backup | =8.1.1.319 | |
Symantec Norton Antivirus with Backup | =8.01.434 | |
Symantec Client Security | =1.1_stm_b8.1.0.825a | |
Symantec Client Security | =1.1.1_mr3_build_8.1.1.323 | |
Symantec Client Security | =1.1.1_mr2_build_8.1.1.319 | |
Symantec Norton Antivirus with Backup | =8.01.471 | |
Symantec Client Security | =1.1.1_mr5_build_8.1.1.336 | |
Symantec Client Security | =2.0 | |
Symantec Client Security | =2.0.3 | |
Symantec Client Security | =2.0_scf_7.1 | |
Symantec Client Security | =1.1.1_mr4_build_8.1.1.329 | |
Symantec Norton Antivirus with Backup | =8.1 | |
Symantec Client Security | =1.1.1_mr6_b8.1.1.266 | |
Symantec Norton Antivirus with Backup | =8.1.1.329 | |
Symantec Norton Antivirus with Backup | =8.1.1.377 | |
Symantec Norton Antivirus with Backup | =8.1.1 | |
Symantec Client Security | =2.0.2 | |
Symantec Client Security | =2.0_stm_build_9.0.0.338 | |
Symantec Client Security | =2.0.1 | |
Symantec Norton Antivirus with Backup | =8.1.1.366 | |
Symantec Client Security | =2.0.2_build_9.0.2.1000-mr2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3455 is considered a critical vulnerability as it allows local users to execute arbitrary code.
To fix CVE-2006-3455, users should upgrade to the latest version of Symantec AntiVirus or Symantec Client Security that addresses this vulnerability.
CVE-2006-3455 affects Symantec AntiVirus Corporate Edition 8.1 and 9.0.x versions up to 9.0.3, as well as Symantec Client Security 1.1 and 2.0.x up to 2.0.3.
CVE-2006-3455 can be exploited by local users with access to the vulnerable system.
If exploited, CVE-2006-3455 can allow an attacker to execute arbitrary code with the privileges of the affected application.