Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
BID:56915
Info
Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 56915 |
| Class: | Unknown |
| CVE: |
CVE-2012-4350 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2012 12:00AM |
| Updated: | Dec 14 2012 07:50AM |
| Credit: | Gavin Jones with NCC Group Ltd |
| Vulnerable: |
Symantec Enterprise Security Manager 10.0.274 Symantec Enterprise Security Manager 9.0.325 Symantec Enterprise Security Manager 6.5.3 Symantec Enterprise Security Manager 6.5.2 Symantec Enterprise Security Manager 6.5.1 Symantec Enterprise Security Manager 5.5.3 Symantec Enterprise Security Manager 6.5 Symantec Enterprise Security Manager 6.0 |
| Not Vulnerable: | |
Discussion
Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
Symantec Enterprise Security Manager and Manager Agent are prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with elevated privileges.
Symantec Enterprise Security Manager and Manager Agent are prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with elevated privileges.
Exploit / POC
Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Symantec Enterprise Security Manager/Agent CVE-2012-4350 Local Privilege Escalation Vulnerability
References:
References: