Symantec PCAnywhere Local Privileged Command Execution Vulnerability
BID:13933
Info
Symantec PCAnywhere Local Privileged Command Execution Vulnerability
| Bugtraq ID: | 13933 |
| Class: | Design Error |
| CVE: |
CVE-2005-1970 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 10 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Symantec pcAnywhere 11.0 Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 Symantec pcAnywhere 9.2 Symantec pcAnywhere 9.0.1 Symantec pcAnywhere 9.0 Symantec pcAnywhere 8.0.2 Symantec pcAnywhere 8.0.1 |
| Not Vulnerable: |
Symantec pcAnywhere 11.5 |
Discussion
Symantec PCAnywhere Local Privileged Command Execution Vulnerability
Symantec pcAnywhere is susceptible to a local privileged command execution
vulnerability. This issue is due to a failure of the application to drop
privileges when executing commands on a users behalf.
This vulnerability allows local attackers to gain unauthorized Local System privileges.
Versions prior to 11.5 are vulnerable to this issue.
Symantec pcAnywhere is susceptible to a local privileged command execution
vulnerability. This issue is due to a failure of the application to drop
privileges when executing commands on a users behalf.
This vulnerability allows local attackers to gain unauthorized Local System privileges.
Versions prior to 11.5 are vulnerable to this issue.
Exploit / POC
Symantec PCAnywhere Local Privileged Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Symantec PCAnywhere Local Privileged Command Execution Vulnerability
Solution:
Symantec has released an advisory, and a patch to address this issue. Please see the referenced advisory for further information.
Users of consumer versions of pcAnywhere should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/files/pca/index.html
Users of enterprise versions of pcAnywhre should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html
Solution:
Symantec has released an advisory, and a patch to address this issue. Please see the referenced advisory for further information.
Users of consumer versions of pcAnywhere should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/files/pca/index.html
Users of enterprise versions of pcAnywhre should visit the following URI to obtain fixes:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html
References
Symantec PCAnywhere Local Privileged Command Execution Vulnerability
References:
References: