peter bassill · operator
$ cve CVE-2006-4927 JSON

CVE-2006-4927 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 1.8% (pctl 77)

Patch early

A public exploit exists.

Description

The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS1.76% — more likely to be exploited than 77% of all CVEs
On CISA KEVno
Public exploityes
Published2006-10-10
Last modified2026-06-16

Affected (2)

VendorProduct
symantecnaveng driver
symantecnavex15 driver

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD