Symantec PCAnywhere Local Privileged Command Execution Vulnerability

BID:13933

Info

Symantec PCAnywhere Local Privileged Command Execution Vulnerability

Bugtraq ID: 13933
Class: Design Error
CVE: CVE-2005-1970
Remote: No
Local: Yes
Published: Jun 10 2005 12:00AM
Updated: Jul 12 2009 02:56PM
Credit: The vendor disclosed this issue.
Vulnerable: Symantec pcAnywhere 11.0
Symantec pcAnywhere 10.5
Symantec pcAnywhere 10.0
Symantec pcAnywhere 9.2
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Symantec pcAnywhere 9.0.1
Symantec pcAnywhere 9.0
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Symantec pcAnywhere 8.0.2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Symantec pcAnywhere 8.0.1
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Not Vulnerable: Symantec pcAnywhere 11.5

Discussion

Symantec PCAnywhere Local Privileged Command Execution Vulnerability

Symantec pcAnywhere is susceptible to a local privileged command execution
vulnerability. This issue is due to a failure of the application to drop
privileges when executing commands on a users behalf.

This vulnerability allows local attackers to gain unauthorized Local System privileges.

Versions prior to 11.5 are vulnerable to this issue.

Exploit / POC

Symantec PCAnywhere Local Privileged Command Execution Vulnerability

An exploit is not required.

Solution / Fix

Symantec PCAnywhere Local Privileged Command Execution Vulnerability

Solution:
Symantec has released an advisory, and a patch to address this issue. Please see the referenced advisory for further information.

Users of consumer versions of pcAnywhere should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/files/pca/index.html

Users of enterprise versions of pcAnywhre should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html

References

Symantec PCAnywhere Local Privileged Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report