RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
BID:33753
Info
RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
| Bugtraq ID: | 33753 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 12 2009 12:00AM |
| Updated: | Feb 17 2009 03:57PM |
| Credit: | Sandeep Cheema |
| Vulnerable: |
Symantec Endpoint Protection 11.0.4000 Symantec Endpoint Protection 11.0 |
| Not Vulnerable: |
Symantec Endpoint Protection 11.0.4000 .2295 |
Discussion
RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
Symantec Endpoint Protection is prone to a local denial-of-service vulnerability.
Attackers may exploit this issue to deny further service to legitimate users.
Endpoint Protection 11.0.4000 is vulnerable; other versions may also be affected.
UPDATE (February 13, 2009): Reports state that exploit attempts against Endpoint Protection 11.0.4000.2295 will cause only the newly formed 'smc.exe' process to crash, with no impact on 'smcgui.exe'.
NOTE: This BID is being retired because the issue is not a vulnerability. The issue as described is not exploitable because privileged processes aren't affected.
Symantec Endpoint Protection is prone to a local denial-of-service vulnerability.
Attackers may exploit this issue to deny further service to legitimate users.
Endpoint Protection 11.0.4000 is vulnerable; other versions may also be affected.
UPDATE (February 13, 2009): Reports state that exploit attempts against Endpoint Protection 11.0.4000.2295 will cause only the newly formed 'smc.exe' process to crash, with no impact on 'smcgui.exe'.
NOTE: This BID is being retired because the issue is not a vulnerability. The issue as described is not exploitable because privileged processes aren't affected.
Exploit / POC
RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
The following example command is available:
smc.exe -p ~
The following example command is available:
smc.exe -p ~
Solution / Fix
RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Symantec Endpoint Protection 'Smc.exe' Local Denial Of Service Vulnerability
References:
References:
- Symantec Homepage (Symantec)
- RE: SEP(Symantec) Bug ("James C. Slora Jr."
) - Re: SEP(Symantec) Bug ([email protected])
- Re: SEPKILL /im SMC.EXE /f ("Sandeep Cheema" <[email protected]>)
- Re: SEPKILL /im SMC.EXE /f ("Sandeep Cheema" <[email protected]>)
- SEP(Symantec) Bug ("Sandeep Cheema" <[email protected]>)
- SEPKILL /im SMC.EXE /f ("Sandeep Cheema" <[email protected]>)
- Re: SEP(Symantec) Bug ("Sandeep Cheema" <[email protected]>)
- RE: SEP(Symantec) Bug ("Jon Kloske"
) - SEPKILL /im SMC.EXE /f ("Sandeep Cheema" <[email protected]>)