First published: Wed Aug 08 2007(Updated: )
Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4) sets incorrect permissions for application files in certain upgrade scenarios, which might allow local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Spam | <=3.0.274.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4206 is considered a medium severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2007-4206, update Kaspersky Anti-Spam to version 3.0.278.4 or later.
CVE-2007-4206 affects Kaspersky Anti-Spam versions up to 3.0.274.0.
Yes, local users can exploit CVE-2007-4206 due to incorrect file permissions set by the application.
There is no specific workaround for CVE-2007-4206 other than upgrading to the patched version.