CVE-2006-0812
CVSS7.2
发布时间 :2006-02-23 15:02:00
修订时间 :2011-03-07 21:30:51
NMCOPS    

[原文]The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.


[CNNVD]VisNetic AntiVirus本地提权漏洞(CNNVD-200602-371)

        用于Mail Server 4.6.0.4、4.6.1.1,还可能包括4.6.1.2之前其他版本的VisNetic AntiVirus插件(DKAVUpSch.exe)在执行其他程序前不降低权限,从而可使本地用户获取权限。

- CVSS (基础分值)

CVSS分值: 7.2 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:visnetic:visnetic_antivirus_plug-in_for_mail_server:4.6.1.1
cpe:/a:visnetic:visnetic_antivirus_plug-in_for_mail_server:4.6.0.4

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0812
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-0812
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200602-371
(官方数据源) CNNVD

- 其它链接及资源

http://secunia.com/advisories/16583
(VENDOR_ADVISORY)  SECUNIA  16583
http://www.vupen.com/english/advisories/2006/0701
(UNKNOWN)  VUPEN  ADV-2006-0701
http://www.securityfocus.com/bid/16788
(UNKNOWN)  BID  16788
http://www.securityfocus.com/archive/1/archive/1/425890/100/0/threaded
(UNKNOWN)  BUGTRAQ  20060223 Secunia Research: Visnetic AntiVirus Plug-in for MailServerPrivilege Escalation
http://securitytracker.com/id?1015670
(UNKNOWN)  SECTRACK  1015670
http://secunia.com/secunia_research/2005-65/advisory/
(VENDOR_ADVISORY)  MISC  http://secunia.com/secunia_research/2005-65/advisory/
http://xforce.iss.net/xforce/xfdb/24928
(UNKNOWN)  XF  visnetic-av-plugin-privilege-elevation(24928)

- 漏洞信息

VisNetic AntiVirus本地提权漏洞
高危 设计错误
2006-02-23 00:00:00 2006-08-16 00:00:00
本地  
        用于Mail Server 4.6.0.4、4.6.1.1,还可能包括4.6.1.2之前其他版本的VisNetic AntiVirus插件(DKAVUpSch.exe)在执行其他程序前不降低权限,从而可使本地用户获取权限。

- 公告与补丁

        厂商已发布了更新来解决此问题。请联系厂商以了解更多信息。

- 漏洞信息 (F44168)

secunia-Visnetic.txt (PacketStormID:F44168)
2006-02-26 00:00:00
 
advisory,arbitrary,local
CVE-2006-0812
[点击下载]

Secunia Research has discovered a vulnerability in the Visnetic AntiVirus Plug-in for MailServer, which can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to the Visnetic AntiVirus Plug-in (DKAVUpSch.exe) not dropping its privileges before invoking other programs. This can be exploited to invoke arbitrary programs on the system with SYSTEM privileges. Versions affected are Visnetic AntiVirus Plug-in for MailServer 4.6.0.4 and 4.6.1.1.

====================================================================== 

                     Secunia Research 23/02/2006

  - Visnetic AntiVirus Plug-in for MailServer Privilege Escalation -

====================================================================== 
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Vendor's Description of Software.....................................3
Description of Vulnerability.........................................4
Solution.............................................................5
Time Table...........................................................6
Credits..............................................................7
References...........................................................8
About Secunia........................................................9
Verification........................................................10

====================================================================== 
1) Affected Software 

Visnetic AntiVirus Plug-in for MailServer 4.6.0.4 and 4.6.1.1.

NOTE: Other versions may also be affected.

====================================================================== 
2) Severity 

Rating: Less critical
Impact: Privilege escalation
Where:  Local system

====================================================================== 
3) Vendor's Description of Software 

"The best means of protecting your organization from email-propagated
viruses is antivirus protection for your mail server. The VisNetic
AntiVirus Plug-in is tightly integrated antivirus protection designed
specifically for VisNetic Mail Server.".

Product Link:
http://www.deerfield.com/products/visnetic-mailserver/antivirus/

====================================================================== 
4) Description of Vulnerability

Secunia Research has discovered a vulnerability in Visnetic AntiVirus
Plug-in for MailServer, which can be exploited by malicious, local
users to gain escalated privileges.

The vulnerability is caused due to the Visnetic AntiVirus Plug-in
(DKAVUpSch.exe) not dropping its privileges before invoking other
programs. This can be exploited to invoke arbitrary programs on the
system with SYSTEM privileges.

====================================================================== 
5) Solution 

Update to version 4.6.1.2.

====================================================================== 
6) Time Table 

07/09/2005 - Vendor notified (1st notice).
07/02/2006 - Vendor notified (2nd notice).
21/02/2006 - Vendor notified (3rd notice).
21/02/2006 - Vendor response.
23/02/2006 - Public disclosure.

====================================================================== 
7) Credits 

Discovered by Secunia Research.

====================================================================== 
8) References

The Common Vulnerabilities and Exposures (CVE) project has assigned
CVE-2006-0812 for the vulnerability.

====================================================================== 
9) About Secunia 

Secunia collects, validates, assesses, and writes advisories regarding 
all the latest software vulnerabilities disclosed to the public. These 
advisories are gathered in a publicly available database at the 
Secunia website: 

http://secunia.com/

Secunia offers services to our customers enabling them to receive all 
relevant vulnerability information to their specific system 
configuration. 

Secunia offers a FREE mailing list called Secunia Security Advisories: 

http://secunia.com/secunia_security_advisories/

====================================================================== 
10) Verification 

Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2005-65/

Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/

======================================================================



    

- 漏洞信息

23381
VisNetic AntiVirus Plug-in for MailServer DKAVUpSch.exe Local Privilege Escalation
Local Access Required
Loss of Integrity Upgrade
Vendor Verified

- 漏洞描述

- 时间线

2006-02-23 2005-09-07
Unknow Unknow

- 解决方案

Upgrade to version 4.6.1.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

VisNetic AntiVirus Local Privilege Escalation Vulnerability
Design Error 16788
No Yes
2006-02-23 12:00:00 2006-02-24 06:02:00
Secunia Research is credited with the discovery of this vulnerability.

- 受影响的程序版本

Deerfield VisNetic AntiVirus 4.6.1 .1
Deerfield VisNetic AntiVirus 4.6 .4
Deerfield VisNetic AntiVirus 4.6.1 .2

- 不受影响的程序版本

Deerfield VisNetic AntiVirus 4.6.1 .2

- 漏洞讨论


VisNetic AntiVirus is prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to launch other applications with SYSTEM privileges. This may facilitate a complete compromise of the affected computer.

- 漏洞利用

An exploit is not required.

- 解决方案

The vendor has released an update addressing this issue. Contact the vendor for further information.

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站