PT-2006-6631 · Alt N Technologies · Mdaemon

Published

2006-11-17

·

Updated

2018-10-17

·

CVE-2006-5968

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MDaemon versions 9.0.5 through 9.0.6, 9.51, and 9.53
Description The issue allows local users to execute arbitrary code by creating malicious RASAPI32.DLL or MPRAPI.DLL libraries in the MDaemonAPP folder. This is due to the MDaemon application folder being installed with insecure permissions, allowing users to create files and directories.
Recommendations For versions 9.0.5 through 9.0.6, 9.51, and 9.53, consider restricting write access to the MDaemonAPP folder to prevent local users from creating malicious libraries. As a temporary workaround, monitor the MDaemonAPP folder for any suspicious RASAPI32.DLL or MPRAPI.DLL files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5968

Affected Products

Mdaemon