VulnerabilityModified
CVE-2006-1355
Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.
HIGH 7.2EPSS 0.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
avast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Affected
- alwil/avast antivirus
- Source
- cve@mitre.org
References
- http://forum.avast.com/index.php?topic=19862.0
- http://secunia.com/advisories/19284Vendor Advisory
- http://www.dslreports.com/forum/remark%2C15601404~days=9999~start=20
- http://www.securityfocus.com/bid/17158
- http://www.vupen.com/english/advisories/2006/1011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25336
- http://forum.avast.com/index.php?topic=19862.0
- http://secunia.com/advisories/19284Vendor Advisory
- http://www.dslreports.com/forum/remark%2C15601404~days=9999~start=20
- http://www.securityfocus.com/bid/17158
- http://www.vupen.com/english/advisories/2006/1011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25336
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.