First published: Sat Sep 09 2006(Updated: )
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying (1) WebProxy.exe or (2) PAVSRV51.EXE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Panda Panda Platinum 2007 Internet Security | =2006_10.02.01 | |
Panda Panda Platinum 2007 Internet Security | =2007_11.00.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4657 is rated as high severity due to its potential for local privilege escalation.
To mitigate CVE-2006-4657, adjust the file permissions of the affected executables to prevent unauthorized access.
CVE-2006-4657 affects Panda Platinum Internet Security versions 2006_10.02.01 and 2007_11.00.00.
Exploitation of CVE-2006-4657 allows local users to gain LocalSystem privileges.
Yes, CVE-2006-4657 can be exploited by local users with access to modify specific service executables.