Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
BID:14542
Info
Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
| Bugtraq ID: | 14542 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 10 2005 12:00AM |
| Updated: | Aug 10 2005 12:00AM |
| Credit: | Jeff Peadro <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Nortel Networks Contivity VPN Client 5.0 1_100 Nortel Networks Contivity VPN Client 5.0 1_030 |
| Not Vulnerable: | |
Discussion
Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
Nortel Contivity VPN Client is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the application to properly lower the privileges of the running process when required.
Due to the nature of the affected application, it executes with SYSTEM privileges. When a local user opens a dialog box to select digital certificates, they may use it to launch arbitrary files.
Due to the failure of the application to properly revert to the users correct privileges, the executed file will be run with SYSTEM privileges.
This vulnerability allows local attackers to access and execute arbitrary files with SYSTEM privileges, facilitating the compromise of the local computer.
Nortel Contivity VPN Client is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the application to properly lower the privileges of the running process when required.
Due to the nature of the affected application, it executes with SYSTEM privileges. When a local user opens a dialog box to select digital certificates, they may use it to launch arbitrary files.
Due to the failure of the application to properly revert to the users correct privileges, the executed file will be run with SYSTEM privileges.
This vulnerability allows local attackers to access and execute arbitrary files with SYSTEM privileges, facilitating the compromise of the local computer.
Exploit / POC
Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
Solution:
The reporter of this issue states that the vendor has released a fix, but this has not been confirmed by Symantec. Users of affected packages should contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of this issue states that the vendor has released a fix, but this has not been confirmed by Symantec. Users of affected packages should contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nortel Contivity VPN Client Local Privilege Escalation Vulnerability
References:
References:
- Contivity VPN Client Homepage (Nortel Networks)
- FW: Updated Version & Exploit - Privilege escalation in Nortel Contivity VPN Cli (Jeff Peadro
) - Privilege escalation in Nortel Contivity VPN Client V05_01.030 (Jeff Peadro
)