The start update window in update.exe in Avira AntiVir PersonalEdition Classic 7.0 build 151 allows local users to gain system privileges via a "Shatter" style attack on the (1) IParam parameter, and the (2) PBM_GETRANGE and (3) PBM_SETRANGE messages in an unspecified progress bar. NOTE: some details are obtained from third party information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/445205/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/19889 | vdb entry |
http://secunia.com/advisories/21764 | third party advisory |
http://www.securityfocus.com/bid/19843 | vdb entry |
http://www.securityfocus.com/archive/1/445263/100/0/threaded | mailing list |