Novell ZENworks System Tray Local Privilege Escalation Vulnerability
BID:11537
Info
Novell ZENworks System Tray Local Privilege Escalation Vulnerability
| Bugtraq ID: | 11537 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Novell ZENworks for Desktops 4.0.1 |
| Not Vulnerable: | |
Discussion
Novell ZENworks System Tray Local Privilege Escalation Vulnerability
It is reported that ZENworks for Desktops contains a local privilege escalation vulnerability.
This vulnerability allows users with local interactive access to execute arbitrary application with administrative privileges.
Version 4.0.1 of the application is reported to be vulnerable to this issue.
It is reported that ZENworks for Desktops contains a local privilege escalation vulnerability.
This vulnerability allows users with local interactive access to execute arbitrary application with administrative privileges.
Version 4.0.1 of the application is reported to be vulnerable to this issue.
Exploit / POC
Novell ZENworks System Tray Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Novell ZENworks System Tray Local Privilege Escalation Vulnerability
Solution:
The vendor has released technical information documents TID-10095153, and TID-2969662, along with a fix to resolve this issue. Please see the referenced documents for further information.
Novell ZENworks for Desktops 4.0.1
Solution:
The vendor has released technical information documents TID-10095153, and TID-2969662, along with a fix to resolve this issue. Please see the referenced documents for further information.
Novell ZENworks for Desktops 4.0.1
-
Novell zfd401_ir5.exe
http://support.novell.com/servlet/filedownload/sec/pub/zfd401_ir5.exe
References
Novell ZENworks System Tray Local Privilege Escalation Vulnerability
References:
References: