CVE-2006-3455: Medium severity Symantec Norton Antivirus vulnerability
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3455?
CVE-2006-3455 is considered a critical vulnerability as it allows local users to execute arbitrary code.
How do I fix CVE-2006-3455?
To fix CVE-2006-3455, users should upgrade to the latest version of Symantec AntiVirus or Symantec Client Security that addresses this vulnerability.
What versions are affected by CVE-2006-3455?
CVE-2006-3455 affects Symantec AntiVirus Corporate Edition 8.1 and 9.0.x versions up to 9.0.3, as well as Symantec Client Security 1.1 and 2.0.x up to 2.0.3.
Who can exploit CVE-2006-3455?
CVE-2006-3455 can be exploited by local users with access to the vulnerable system.
What is the impact of CVE-2006-3455 if exploited?
If exploited, CVE-2006-3455 can allow an attacker to execute arbitrary code with the privileges of the affected application.