CVE-2006-4266 describes a vulnerability in Symantec Norton Personal Firewall 2006 (and potentially earlier versions) where it fails to adequately protect its own registry keys. This allows a local user with administrative privileges to inject malicious libraries, such as NISProd.dll, by manipulating the HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners registry key. While requiring administrative access, this is considered a vulnerability because the product's function is to protect against such actions, leading to a CVSS score of 3.6 with potential for partial confidentiality and integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2006_9.1.0.33CPE matchmatch criteria | cpe:2.3:a:symantec:norton_personal_firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.