CVE-2016-6590
Summary
| CVE | CVE-2016-6590 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-08 16:15:00 UTC |
| Updated | 2020-01-21 14:24:00 UTC |
| Description | A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Encryption Desktop | All | All | All | All |
| Application | Symantec | Encryption Desktop | All | All | All | All |
| Application | Symantec | Endpoint Encryption | All | All | All | All |
| Application | Symantec | Endpoint Encryption | 7.6 | All | All | All |
| Application | Symantec | Endpoint Encryption | All | All | All | All |
| Application | Symantec | Endpoint Encryption | 7.6 | All | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | - | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack1 | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack2 | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack3 | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | - | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack1 | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack2 | All | All |
| Application | Symantec | Ghost Solution Suite | 3.1 | maintenance_pack3 | All | All |
| Application | Symantec | It Management Suite | 7.6 | All | All | All |
| Application | Symantec | It Management Suite | 8.0 | All | All | All |
| Application | Symantec | It Management Suite | 7.6 | All | All | All |
| Application | Symantec | It Management Suite | 8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Symantec Products CVE-2016-6590 DLL Loading Local Privilege Escalation Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Coreutils: Arbitrary code execution (GLSA 201612-22) — Gentoo security | CONFIRM | support.symantec.com | Vendor Advisory |
| Symantec Ghost Suite DLL Loading Error Lets Local Users Gain Elevated Privileges - SecurityTracker | MISC | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.