CVE-2006-1380Interscan Messaging Security Suite vulnerability

CWE-2643 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 78.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 1

Description

ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9gph-vqx2-84w8: ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 52022-05-01
CVEList
CVE-2006-1380: ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 52006-03-24
CVE-2006-1380 — Trendmicro vulnerability | cvebase