Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
BID:56847
Info
Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 56847 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-4349 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 10 2012 12:00AM |
| Updated: | Dec 17 2012 06:40PM |
| Credit: | Gavin Jones with NCC Group Ltd. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
Symantec Network Access Control is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with elevated privileges. Failed exploit attempts will result in a denial-of-service condition.
Symantec Network Access Control is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with elevated privileges. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Symantec Network Access Control CVE-2012-4349 Local Privilege Escalation Vulnerability
References:
References:
- Symantec Homepage (Symantec Corp.)