Lucene search

K
cveMitreCVE-2006-2273
HistoryMay 12, 2006 - 12:02 a.m.

CVE-2006-2273

2006-05-1200:02:00
mitre
web.nvd.nist.gov
28
verisign
vupdater
install
activex
security
vulnerability
remote execution
cab
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

High

EPSS

0.043

Percentile

92.3%

The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable file.

Affected configurations

Nvd
Node
verisigni-nav
VendorProductVersionCPE
verisigni-nav*cpe:2.3:a:verisign:i-nav:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

High

EPSS

0.043

Percentile

92.3%