CVE-2006-3697

N/A Unknown
Published: July 21, 2006 Modified: April 16, 2026
View on NVD

Description

Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and execute commands (a) via the "open folder" option when no instance of explorer.exe is running, possibly related to the ShellExecute API function; or (b) by overwriting a batch file through the "Save Configuration As" option. NOTE: this might be a vulnerability in Microsoft Windows and explorer.exe instead of the firewall.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/21088
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/21089
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/27349
Source: cve@mitre.org
http://www.vupen.com/english/advisories/2006/2851
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2006/2852
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2007/0144
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/21088
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/21089
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.ben.goulding.com.au/secad.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27349
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/440426/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/19018
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/19024
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/2851
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vupen.com/english/advisories/2006/2852
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vupen.com/english/advisories/2007/0144
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.1%
21th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

lavasoft novell agnitum