{ "id": "CVE-2006-0255", "sourceIdentifier": "cve@mitre.org", "published": "2006-01-18T01:51:00.000", "lastModified": "2024-11-21T00:06:02.033", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious \"program.exe\" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "baseScore": 7.2, "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE" }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:*:*:fp1:*:*:*:*:*", "matchCriteriaId": "426A6759-491C-461D-A850-7168F7D04CA7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:*:*:*:*:*:*:*", "matchCriteriaId": "0219DD2D-A37D-4425-9436-4F3DA1B7F63D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp1:*:*:*:*:*:*", "matchCriteriaId": "7D2582AE-B67A-45DF-B798-8A0426613BDD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp2:*:*:*:*:*:*", "matchCriteriaId": "16F333AD-6A2B-4E91-8BE3-0896DCCB8693" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp3:*:*:*:*:*:*", "matchCriteriaId": "B9754CCE-CEC5-4359-9C62-133885817DEF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp4:*:*:*:*:*:*", "matchCriteriaId": "C65FC343-69C9-4B70-8149-42297B47C813" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp5:*:*:*:*:*:*", "matchCriteriaId": "82B9036B-CE8D-47B3-B742-33C4B8B05ED2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp5a:*:*:*:*:*:*", "matchCriteriaId": "610F8305-9CD7-48F2-9F2E-2CDECD623DBE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkpoint:vpn-1:4.1:sp6:*:*:*:*:*:*", "matchCriteriaId": "96CED910-99F7-43C5-83F8-68D3C0641F03" } ] } ] } ], "references": [ { "url": "http://secdev.zoller.lu/research/checkpoint.txt", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/422263/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/16290", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2006/0258", "source": "cve@mitre.org" }, { "url": "http://secdev.zoller.lu/research/checkpoint.txt", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/archive/1/422263/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/16290", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2006/0258", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }