ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
References
Configurations
Information
Published : 2006-03-24 03:02
Updated : 2017-07-19 18:30
NVD link : CVE-2006-1380
Mitre link : CVE-2006-1380
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
trendmicro
- interscan_messaging_security_suite