Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
BID:11717
Info
Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
| Bugtraq ID: | 11717 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 20 2004 12:00AM |
| Updated: | Nov 20 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Cengiz Aykanat. |
| Vulnerable: |
Computer Associates eTrust EZ Antivirus 7.0.2 Computer Associates eTrust EZ Antivirus 7.0.1 Computer Associates eTrust EZ Antivirus 7.0 Computer Associates eTrust EZ Antivirus 6.3 Computer Associates eTrust EZ Antivirus 6.2 Computer Associates eTrust EZ Antivirus 6.1 |
| Not Vulnerable: |
Computer Associates eTrust EZ Antivirus 7.0.2 .1 |
Discussion
Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
A local authentication bypass vulnerability affects the user interface of eTrust EZAntivirus. This issue is due to a design error that allows a local attacker to bypass the implemented authentication.
A local attacker may exploit this issue to bypass the user interface authentication mechanisms, facilitating unauthorized access the software. This may allow manipulation of virus scanning rules that may subsequently facilitate further attacks against the affected computer.
A local authentication bypass vulnerability affects the user interface of eTrust EZAntivirus. This issue is due to a design error that allows a local attacker to bypass the implemented authentication.
A local attacker may exploit this issue to bypass the user interface authentication mechanisms, facilitating unauthorized access the software. This may allow manipulation of virus scanning rules that may subsequently facilitate further attacks against the affected computer.
Exploit / POC
Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
Solution:
Version 7.0.2.1 has been released by the vendor to resolve this issue. Users of affected packages should contact the vendor for futher information on obtaining fixes.
Computer Associates has released an advisory for this issue. Please see the referenced advisory for further information.
Solution:
Version 7.0.2.1 has been released by the vendor to resolve this issue. Users of affected packages should contact the vendor for futher information on obtaining fixes.
Computer Associates has released an advisory for this issue. Please see the referenced advisory for further information.
References
Computer Associates eTrust EZAntivirus User Interface Local Authentication Bypass Vulnerability
References:
References:
- eTrust EZ Antivirus GUI password protection bypass vulnerability (Computer Associates)
- eTrust EZAntivirus Home Page (Computer Associates)