|
|
>> NOD32 Scheduler and File Restoration Local Privilege Escalation Vulnerabilities
|
Title : NOD32 Scheduler and File Restoration Local Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2006-1242 CVE ID : CVE-2006-0951 - CVE-2006-1649
Rated as : Moderate Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-04-05
|
Two vulnerabilities have been identified in NOD32, which could be exploited by local attackers to obtain elevated privileges.
The first issue is due to an error in the GUI ("nod32.exe") that runs with SYSTEM privileges when a scheduled scan is being run by the scheduler, which could be exploited by malicious users to execute arbitrary binaries (e.g. cmd.exe) with SYSTEM privileges when a scheduled scan is running.
The second flaw is due to an error in the "Restore to..." feature that fails to drop privileges before restoring a quarantined file, which could be exploited by malicious users to write malicious files to arbitrary directories with SYSTEM privileges.
Affected Products
NOD32 for Windows NT/2000/XP/2003 versions prior to 2.51.26
Solution
Upgrade to NOD32 version 2.51.26 :
http://www.nod32.com/download/download.htm
References
http://www.vupen.com/english/advisories/2006/1242 http://secunia.com/secunia_research/2006-17/advisory/
Credits
Vulnerabilities reported by Tan Chew Keong and Bipin Gautam
ChangeLog
2006-04-05 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|