Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
BID:27146
Info
Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27146 |
| Class: | Design Error |
| CVE: |
CVE-2007-5665 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 04 2008 12:00AM |
| Updated: | Jan 07 2008 10:09PM |
| Credit: | Stephen Fewer of Harmony Security is credited with discovering this issue. |
| Vulnerable: |
Novell ZENworks Endpoint Security Management 3.5.0.20 |
| Not Vulnerable: |
Novell ZENworks Endpoint Security Management 3.5.0.82 |
Discussion
Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
Novell ZENworks ESM (Endpoint Security Management) Security Client is prone to a local privilege-escalation vulnerability.
Exploiting this vulnerability allows local attackers to execute arbitrary malicious code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.
This issue affects ZENworks Endpoint Security Management 3.5.0.20; other versions may also be affected.
Novell ZENworks ESM (Endpoint Security Management) Security Client is prone to a local privilege-escalation vulnerability.
Exploiting this vulnerability allows local attackers to execute arbitrary malicious code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.
This issue affects ZENworks Endpoint Security Management 3.5.0.20; other versions may also be affected.
Exploit / POC
Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
To exploit this issue, attackers can use readily available tools.
To exploit this issue, attackers can use readily available tools.
Solution / Fix
Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for information about obtaining and applying the updates.
Solution:
The vendor released an update to address this issue. Please contact the vendor for information about obtaining and applying the updates.
References
Novell ZENworks ESM Security Client 'STEngine.exe' Local Privilege Escalation Vulnerability
References:
References: