Vulnerability Description
Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious "program" file in the C: folder.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Starforce | Safe N Sec Personal \+ Anti-Spyware | <= 2.0 |
References
- http://secdev.zoller.lu/research/safnsec.htm
- http://www.securityfocus.com/archive/1/425504/100/0/threaded
- http://www.securityfocus.com/bid/16762
- http://secdev.zoller.lu/research/safnsec.htm
- http://www.securityfocus.com/archive/1/425504/100/0/threaded
- http://www.securityfocus.com/bid/16762
FAQ
What is CVE-2006-0858?
CVE-2006-0858 is a vulnerability with a CVSS score of 7.2 (HIGH). Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earl...
How severe is CVE-2006-0858?
CVE-2006-0858 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0858?
Check the references section above for vendor advisories and patch information. Affected products include: Starforce Safe N Sec Personal \+ Anti-Spyware.