CVE-2006-4927

Symantec AntiVirus <20061.3.0.12 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-4927. PoCs published by Ruben Santamarta.

AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in Symantec AntiVirus products by corrupting memory to execute arbitrary code with kernel-level privileges. It manipulates the mmUserProbeAddress and ExRaiseAccessViolation to achieve code execution in Ring0.

Description

The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Ruben Santamarta · clocalwindows
https://www.exploit-db.com/exploits/28764

This exploit targets a privilege escalation vulnerability in Symantec AntiVirus products by corrupting memory to execute arbitrary code with kernel-level privileges. It manipulates the mmUserProbeAddress and ExRaiseAccessViolation to achieve code execution in Ring0.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Symantec AntiVirus and Norton antivirus products on Windows NT, 2000, and XP
No auth needed
Prerequisites: Local access to the target system · Symantec AntiVirus or Norton antivirus installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Ruben Santamarta · clocalwindows
https://www.exploit-db.com/exploits/28763

This exploit targets a privilege escalation vulnerability in Symantec AntiVirus (CVE-2006-4927) by corrupting memory via the NAVENG device driver, allowing arbitrary code execution with kernel-level privileges. It overwrites the NtQuerySystemInformation switch to execute a shellcode payload.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Symantec AntiVirus (Norton Internet Security) on Windows NT, 2000, and XP
No auth needed
Prerequisites: Local access to the target system · Symantec AntiVirus with vulnerable NAVENG driver loaded
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (18)

Core 18
Core References
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016996
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/447849/100/0/threaded
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017001
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017000
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016997
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016995
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3928
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016998
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=417
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016994
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22288
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20360
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016999
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017002
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1690
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29360
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/946820

Scores

EPSS 0.0166
EPSS Percentile 73.6%

Details

Status published
Products (2)
symantec/naveng_driver
symantec/navex15_driver
Published Oct 10, 2006
Tracked Since Feb 18, 2026