CVE-2006-3455
Summary
| CVE | CVE-2006-3455 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-23 20:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:L/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Client Security | 1.1 | All | All | All |
| Application | Symantec | Client Security | 1.1.1 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_build_393 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr1_build_8.1.1.314a | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr2_build_8.1.1.319 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr3_build_8.1.1.323 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr4_build_8.1.1.329 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr5_build_8.1.1.336 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr6_b8.1.1.266 | All | All | All |
| Application | Symantec | Client Security | 1.1_stm_b8.1.0.825a | All | All | All |
| Application | Symantec | Client Security | 2.0 | All | All | All |
| Application | Symantec | Client Security | 2.0.1 | All | All | All |
| Application | Symantec | Client Security | 2.0.1_build_9.0.1.1000 | mr1 | All | All |
| Application | Symantec | Client Security | 2.0.2 | All | All | All |
| Application | Symantec | Client Security | 2.0.2_build_9.0.2.1000 | mr2 | All | All |
| Application | Symantec | Client Security | 2.0.3 | All | All | All |
| Application | Symantec | Client Security | 2.0.3_build_9.0.3.1000 | mr3 | All | All |
| Application | Symantec | Client Security | 2.0_scf_7.1 | All | All | All |
| Application | Symantec | Client Security | 2.0_stm_build_9.0.0.338 | All | All | All |
| Application | Symantec | Norton Antivirus | 8.01.434 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.437 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.446 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.457 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.460 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.464 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.471 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.0.825a | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.319 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.323 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.329 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.366 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.377 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1_build393 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1_build8.1.1.314a | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1.1.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2.1000 | All | corporate | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec Products SAVRT.SYS Device Driver Privilege Escalation - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Symantec AntiVirus SAVRT.SYS Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Symantec Device Driver Elevation of Privilege | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Patch |
| Symantec Client Security SAVRT.SYS Device Driver Buffer Overflow Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Symantec Anti Virus Corporate Edition SAVRT.SYS Device Driver Buffer Overflow Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.