PT-2006-2152 · Grisoft · Avg Free

Publicado

2006-03-09

·

Atualizado

2017-07-20

·

CVE-2006-1125

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grisoft AVG Free versions 7.0.308 through 7.1
Description The issue allows local users to potentially gain privileges due to the setting of Everyone/Full Control permissions for certain update files, including upd vers.cfg and incavi.avm, as well as unspecified drivers.
Recommendations For Grisoft AVG Free version 7.1, consider restricting access to the update files upd vers.cfg, incavi.avm, and the unspecified drivers to minimize the risk of exploitation. For Grisoft AVG Free version 7.0.308, restrict access to the same files as mentioned for version 7.1 to prevent potential privilege escalation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1125

Produtos afetados

Avg Free