Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
BID:11873
Info
Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
| Bugtraq ID: | 11873 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Dec 13 2004 12:00AM |
| Credit: | Discovery is credited to Secure Network Operations security team. |
| Vulnerable: |
Symantec Norton SystemWorks 2004 Symantec Norton SystemWorks 2003 Symantec Norton SystemWorks 2002 Symantec Norton SystemWorks 2001 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Norton Internet Security 2001 Professional Edition Symantec Norton Internet Security 2001 0 Symantec Norton AntiVirus 2004 Professional Edition Symantec Norton AntiVirus 2004 Symantec Norton AntiVirus 2003 Professional Edition Symantec Norton Antivirus 2003 0 Symantec Norton AntiVirus 2002 Professional Edition Symantec Norton AntiVirus 2002 0 Symantec Norton AntiVirus 2001 Professional Edition Symantec Norton AntiVirus 2001 0 Symantec LiveUpdate 2.0 Symantec LiveUpdate 1.80.19 .0 Symantec LiveUpdate 1.9 Symantec LiveUpdate 1.8 Symantec LiveUpdate 1.7 Symantec LiveUpdate 1.6 Symantec LiveUpdate 1.5 Symantec LiveUpdate 1.4 Symantec AntiVirus for Handhelds Corporate Edition 3.0 Symantec AntiVirus for Handhelds 3.0 |
| Not Vulnerable: |
Symantec LiveUpdate 2.5 Symantec Java LiveUpdate |
Discussion
Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
Symantec Windows LiveUpdate is reported prone to a local privilege escalation vulnerability. This issue can allow a local unprivileged attacker to gain administrative privileges on a vulnerable computer.
It is reported that this issue only presents itself during an interactive LiveUpdate session. A local attacker may influence the LiveUpdate GUI Internet options configuration functionality in a manner that grants them elevated privileges.
This issue affects Windows LiveUpdate on computers running retail versions of Symantec products and Symantec AntiVirus for Handhelds Corporate Edition v3.0.
Symantec Windows LiveUpdate is reported prone to a local privilege escalation vulnerability. This issue can allow a local unprivileged attacker to gain administrative privileges on a vulnerable computer.
It is reported that this issue only presents itself during an interactive LiveUpdate session. A local attacker may influence the LiveUpdate GUI Internet options configuration functionality in a manner that grants them elevated privileges.
This issue affects Windows LiveUpdate on computers running retail versions of Symantec products and Symantec AntiVirus for Handhelds Corporate Edition v3.0.
Exploit / POC
Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
Solution:
Symantec has released Windows LiveUpdate 2.5 to address this issue. This version can be automatically installed on vulnerable systems by running LiveUpdate. It is also available for download from the following location:
http://www.symantec.com/techsupp/files/lu/lu.html
Solution:
Symantec has released Windows LiveUpdate 2.5 to address this issue. This version can be automatically installed on vulnerable systems by running LiveUpdate. It is also available for download from the following location:
http://www.symantec.com/techsupp/files/lu/lu.html
References
Symantec Windows LiveUpdate Local Privilege Escalation Vulnerability
References:
References:
- SYM04-018 - Symantec Windows LiveUpdate Elevation of Privilege (Symantec)
- Symantec Homepage (Symantec)
- Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec Li ("Secure Network Operations, Inc."
)