Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
BID:14524
Info
Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
| Bugtraq ID: | 14524 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2017 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 09 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to an anonymous source. |
| Vulnerable: |
Symantec Client Security 2.0.2 MR2 b9.0.2.1000 Symantec Client Security 2.0.1 MR1 b9.0.1.1000 Symantec Client Security 2.0 STM build 9.0.0.338 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 2.0 Symantec AntiVirus Corporate Edition 9.0.2 .1000 Symantec AntiVirus Corporate Edition 9.0.1 .1.1000 Symantec AntiVirus Corporate Edition 9.0 .0.338 Symantec AntiVirus Corporate Edition 9.0 |
| Not Vulnerable: |
Symantec Client Security 3.0 Symantec Client Security 2.0.3 MR3 b9.0.3.1000 Symantec Client Security 1.1.1 MR5 build 8.1.1.336 Symantec Client Security 1.1.1 MR4 build 8.1.1.329 Symantec Client Security 1.1.1 MR3 build 8.1.1.323 Symantec Client Security 1.1.1 MR2 build 8.1.1.319 Symantec Client Security 1.1.1 MR1 build 8.1.1.314a Symantec Client Security 1.1.1 MR6 b8.1.1.266 Symantec Client Security 1.1.1 Symantec Client Security 1.1 STM b8.1.0.825a Symantec Client Security 1.1 Symantec Client Security 1.0.1 MR8 build 8.01.471 Symantec Client Security 1.0.1 MR7 build 8.01.464 Symantec Client Security 1.0.1 MR6 build 8.01.460 Symantec Client Security 1.0.1 MR5 build 8.01.457 Symantec Client Security 1.0.1 MR4 build 8.01.446 Symantec Client Security 1.0.1 MR3 build 8.01.434 Symantec Client Security 1.0.1 build 8.01.437 Symantec Client Security 1.0.1 MR9 b8.01.501 Symantec Client Security 1.0.1 MR2 b8.01.429c Symantec Client Security 1.0.1 MR1 b8.01.425a/b Symantec Client Security 1.0.1 Symantec Client Security 1.0 .0 b8.01.9378 Symantec Client Security 1.0 b8.01.9374 Symantec Client Security 1.0 Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 9.0.3 .1000 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.329 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.323 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.319 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.314a Symantec AntiVirus Corporate Edition 8.1.1 .366 Symantec AntiVirus Corporate Edition 8.1.1 Symantec AntiVirus Corporate Edition 8.1 build 8.01.471 Symantec AntiVirus Corporate Edition 8.1 build 8.01.464 Symantec AntiVirus Corporate Edition 8.1 build 8.01.460 Symantec AntiVirus Corporate Edition 8.1 build 8.01.457 Symantec AntiVirus Corporate Edition 8.1 build 8.01.446 Symantec AntiVirus Corporate Edition 8.1 build 8.01.437 Symantec AntiVirus Corporate Edition 8.1 build 8.01.434 Symantec AntiVirus Corporate Edition 8.1 .0.825a Symantec AntiVirus Corporate Edition 8.1 Symantec AntiVirus Corporate Edition 8.0 1.9378 Symantec AntiVirus Corporate Edition 8.0 1.9374 Symantec AntiVirus Corporate Edition 8.0 1.501 Symantec AntiVirus Corporate Edition 8.0 1.429c Symantec AntiVirus Corporate Edition 8.0 1.425a/b Symantec AntiVirus Corporate Edition 8.0 1 Symantec AntiVirus Corporate Edition 8.0 |
Discussion
Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
Symantec AntiVirus Corporate Edition is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the application to properly lower the privileges of the running process when required.
Due to the nature of the affected application, it executes with SYSTEM privileges. When a local user opens the HTML help browser from the affected application, it is executed with the same elevated privileges as the calling application.
This vulnerability allows local attackers to access and execute arbitrary files with SYSTEM privileges, facilitating the compromise of the local computer.
Symantec AntiVirus Corporate Edition is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the application to properly lower the privileges of the running process when required.
Due to the nature of the affected application, it executes with SYSTEM privileges. When a local user opens the HTML help browser from the affected application, it is executed with the same elevated privileges as the calling application.
This vulnerability allows local attackers to access and execute arbitrary files with SYSTEM privileges, facilitating the compromise of the local computer.
Exploit / POC
Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
Solution:
An advisory, along with fixes are available from the vendor. Please see the referenced advisory for further information.
Solution:
An advisory, along with fixes are available from the vendor. Please see the referenced advisory for further information.
References
Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulnerability
References:
References: