Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
BID:53903
Info
Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
| Bugtraq ID: | 53903 |
| Class: | Design Error |
| CVE: |
CVE-2012-0304 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 15 2012 12:00AM |
| Updated: | Sep 11 2012 12:50AM |
| Credit: | Tenable Network Security |
| Vulnerable: |
Symantec LiveUpdate Administrator 2.3 Symantec LiveUpdate Administrator 2.2.2.9 |
| Not Vulnerable: | |
Discussion
Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
Symantec LiveUpdate Administrator is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with elevated privileges on the system.
Symantec LiveUpdate Administrator 2.3.1 and prior are vulnerable.
Symantec LiveUpdate Administrator is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with elevated privileges on the system.
Symantec LiveUpdate Administrator 2.3.1 and prior are vulnerable.
Exploit / POC
Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
An attacker can use readily available command-line utilities to exploit this issue.
An attacker can use readily available command-line utilities to exploit this issue.
Solution / Fix
Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec LiveUpdate Administrator Insecure File Permissions Local Privilege Escalation Vulnerability
References:
References: