CVE-2006-4927
Summary
| CVE | CVE-2006-4927 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-10 04:06:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Naveng Driver | All | All | All | All |
| Application | Symantec | Navex15 Driver | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec Antivirus Engine Privilege Escalation - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityTracker.com Archives - Symantec Mail Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| US-CERT Vulnerability Note VU#946820 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Symantec Products IOCTL Handler Privilege Escalation - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Symantec Anti Virus NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| SecurityTracker.com Archives - Symantec Web Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| Symantec AntiVirus IOCTL Kernel Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| SecurityTracker.com Archives - Norton Internet Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| Accenture | Let there be change | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | Patch, Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - Norton Anti-Virus NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| SecurityTracker.com Archives - Symantec Scan Engine NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - Norton System Works NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| SecurityTracker.com Archives - Symantec Client Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Symantec Brightmail NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.