Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
BID:51592
Info
Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
| Bugtraq ID: | 51592 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3478 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2012 12:00AM |
| Updated: | Jun 27 2012 04:30PM |
| Credit: | Tal Zeltzer and Edward Torkington |
| Vulnerable: |
Symantec pcAnywhere Solution 12.6 Symantec pcAnywhere Solution 12.5 Symantec pcAnywhere 11.5.1 Symantec pcAnywhere 11.5 Symantec pcAnywhere 11.0.1 Symantec pcAnywhere 11.0 Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 Symantec pcAnywhere 12.5 SP3 Symantec pcAnywhere 12.5 SP1 Symantec pcAnywhere 12.5 Symantec pcAnywhere 12.1 Symantec pcAnywhere 12.0 |
| Not Vulnerable: |
Symantec pcAnywhere Solution 12.6.7 Symantec pcAnywhere 12.5 SP4 |
Discussion
Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
pcAnywhere is prone to a remote code-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code in the context of the affected application. This may facilitate a complete compromise of the affected computer.
pcAnywhere 12.5 versions are affected; other versions may also be affected.
pcAnywhere is prone to a remote code-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code in the context of the affected application. This may facilitate a complete compromise of the affected computer.
pcAnywhere 12.5 versions are affected; other versions may also be affected.
Exploit / POC
Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Symantec pcAnywhere Host Services Remote Code Execution Vulnerability
References:
References:
- pcAnywhere Homepage (Symantec)
- pcAnywhere hotfix (Symantec)
- SYM12-002 Security Advisories Relating to Symantec Products - Symantec pcAnywher (Symantec)
- ZDI-12-018 Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability (Zero Day Initiative)