PT-2006-1904 · Microsoft+1 · Windows+1
Thierry Zoller
·
Published
2006-02-23
·
Updated
2018-10-18
·
CVE-2006-0858
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
StarForce Safe'n'Sec Personal + Anti-Spyware versions 2.0 and earlier
Description
The issue is related to an unquoted Windows search path vulnerability in multiple components, including snsmcon.exe, the autostartup mechanism, and an unspecified installation component. This could potentially allow local users to gain privileges by placing a malicious "program" file in the C: folder.
Recommendations
For StarForce Safe'n'Sec Personal + Anti-Spyware versions 2.0 and earlier, consider restricting access to the C: folder to prevent malicious files from being placed there, and avoid using the autostartup mechanism until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Starforce Safe'N'Sec Personal + Anti-Spyware
Windows