CVE-2006-4657: High severity Panda Panda Platinum Internet Security vulnerability
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying (1) WebProxy.exe or (2) PAVSRV51.EXE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4657?
CVE-2006-4657 is rated as high severity due to its potential for local privilege escalation.
How do I fix CVE-2006-4657?
To mitigate CVE-2006-4657, adjust the file permissions of the affected executables to prevent unauthorized access.
Which versions of Panda Platinum Internet Security are affected by CVE-2006-4657?
CVE-2006-4657 affects Panda Platinum Internet Security versions 2006_10.02.01 and 2007_11.00.00.
What types of privileges can be obtained through CVE-2006-4657?
Exploitation of CVE-2006-4657 allows local users to gain LocalSystem privileges.
Is there a known exploit for CVE-2006-4657?
Yes, CVE-2006-4657 can be exploited by local users with access to modify specific service executables.