PT-2006-2152 · Grisoft · Avg Free
Published
2006-03-09
·
Updated
2017-07-20
·
CVE-2006-1125
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Grisoft AVG Free versions 7.0.308 through 7.1
Description
The issue allows local users to potentially gain privileges due to the setting of Everyone/Full Control permissions for certain update files, including
upd vers.cfg and incavi.avm, as well as unspecified drivers.Recommendations
For Grisoft AVG Free version 7.1, consider restricting access to the update files
upd vers.cfg, incavi.avm, and the unspecified drivers to minimize the risk of exploitation.
For Grisoft AVG Free version 7.0.308, restrict access to the same files as mentioned for version 7.1 to prevent potential privilege escalation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avg Free