CVE-2006-3455
Last modified
CVE-2006-3455 is a vulnerability of currently unknown severity. The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symantec | Client Security | 1.1 | — |
| Symantec | Client Security | 1.1.1 | — |
| Symantec | Client Security | 1.1.1_build_393 | — |
| Symantec | Client Security | 1.1.1_mr1_build_8.1.1.314a | — |
| Symantec | Client Security | 1.1.1_mr2_build_8.1.1.319 | — |
| Symantec | Client Security | 1.1.1_mr3_build_8.1.1.323 | — |
| Symantec | Client Security | 1.1.1_mr4_build_8.1.1.329 | — |
| Symantec | Client Security | 1.1.1_mr5_build_8.1.1.336 | — |
| Symantec | Client Security | 1.1.1_mr6_b8.1.1.266 | — |
| Symantec | Client Security | 1.1_stm_b8.1.0.825a | — |
| Symantec | Client Security | 2.0 | — |
| Symantec | Client Security | 2.0.1 | — |
| Symantec | Client Security | 2.0.1_build_9.0.1.1000 | Mr1 |
| Symantec | Client Security | 2.0.2 | — |
| Symantec | Client Security | 2.0.2_build_9.0.2.1000 | Mr2 |
| Symantec | Client Security | 2.0.3 | — |
| Symantec | Client Security | 2.0.3_build_9.0.3.1000 | Mr3 |
| Symantec | Client Security | 2.0_scf_7.1 | — |
| Symantec | Client Security | 2.0_stm_build_9.0.0.338 | — |
| Symantec | Norton Antivirus | 8.1 | — |
| Symantec | Norton Antivirus | 8.1.0.825a | — |
| Symantec | Norton Antivirus | 8.1.1 | — |
| Symantec | Norton Antivirus | 8.1.1.319 | — |
| Symantec | Norton Antivirus | 8.1.1.323 | — |
| Symantec | Norton Antivirus | 8.1.1.329 | — |
| Symantec | Norton Antivirus | 8.1.1.366 | — |
| Symantec | Norton Antivirus | 8.1.1.377 | — |
| Symantec | Norton Antivirus | 8.1.1_build8.1.1.314a | — |
| Symantec | Norton Antivirus | 8.1.1_build393 | — |
| Symantec | Norton Antivirus | 8.01.434 | — |
| Symantec | Norton Antivirus | 8.01.437 | — |
| Symantec | Norton Antivirus | 8.01.446 | — |
| Symantec | Norton Antivirus | 8.01.457 | — |
| Symantec | Norton Antivirus | 8.01.460 | — |
| Symantec | Norton Antivirus | 8.01.464 | — |
| Symantec | Norton Antivirus | 8.01.471 | — |
| Symantec | Norton Antivirus | 9.0.1 | — |
| Symantec | Norton Antivirus | 9.0.1.1.1000 | — |
| Symantec | Norton Antivirus | 9.0.1.1000 | — |
| Symantec | Norton Antivirus | 9.0.2 | — |
| Symantec | Norton Antivirus | 9.0.2.1000 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3455?
How severe is CVE-2006-3455?
How do I fix CVE-2006-3455?
Are you affected by CVE-2006-3455?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
