Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
BID:11709
Info
Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
| Bugtraq ID: | 11709 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 19 2004 12:00AM |
| Updated: | Nov 19 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Reed Arvin <[email protected]>. |
| Vulnerable: |
Altiris Deployment Solution 5.6 SP1 (Hotfix E) |
| Not Vulnerable: | |
Discussion
Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
Altiris Deployment Solution Client allows a user to activate the client interface by easily launching the software from an icon in the Windows system tray. It is reported that a local user may exploit the client interface to escalate privileges.
It should be noted that although this vulnerability is reported to exist in Altiris Deployment Solution version 5.6 SP1 (Hotfix E) other versions might also be affected.
Altiris Deployment Solution Client allows a user to activate the client interface by easily launching the software from an icon in the Windows system tray. It is reported that a local user may exploit the client interface to escalate privileges.
It should be noted that although this vulnerability is reported to exist in Altiris Deployment Solution version 5.6 SP1 (Hotfix E) other versions might also be affected.
Exploit / POC
Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
No exploit is required. The following example is available:
1. Right click on the Altiris Client Service icon in the Taskbar and choose View Log File
2. Notepad should open. Click File, click Open
3. In the Files of type: field choose All Files
4. Navagate to '%WINDIR%\System32'. Right click on 'cmd.exe' and choose Open
6. A new command shell with launch with SYSTEM privileges
No exploit is required. The following example is available:
1. Right click on the Altiris Client Service icon in the Taskbar and choose View Log File
2. Notepad should open. Click File, click Open
3. In the Files of type: field choose All Files
4. Navagate to '%WINDIR%\System32'. Right click on 'cmd.exe' and choose Open
6. A new command shell with launch with SYSTEM privileges
Solution / Fix
Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Altiris Deployment Solution Client Service Local Privilege Escalation Vulnerability
References:
References: