Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
BID:6315
Info
Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
| Bugtraq ID: | 6315 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 18 2002 12:00AM |
| Updated: | Nov 18 2002 12:00AM |
| Credit: | This vulnerability first reported in a Computer Associates bulletin. |
| Vulnerable: |
Computer Associates eTrust Antivirus EE 6.0 |
| Not Vulnerable: | |
Discussion
Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
Computer Associates eTrust Antivirus EE, under some circumstances, may allow attackers to obtain elevated privileges.
If a specially crafted commandline argument is passed, it may be possible to trick eTrust into executing a different program than the one intended.
Thus, it is possible to cause eTrust to execute an attacker-supplied program with the privileges of the calling process, typically SYSTEM.
Computer Associates eTrust Antivirus EE, under some circumstances, may allow attackers to obtain elevated privileges.
If a specially crafted commandline argument is passed, it may be possible to trick eTrust into executing a different program than the one intended.
Thus, it is possible to cause eTrust to execute an attacker-supplied program with the privileges of the calling process, typically SYSTEM.
Exploit / POC
Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
Solution:
Fixes available:
Computer Associates eTrust Antivirus EE 6.0
Solution:
Fixes available:
Computer Associates eTrust Antivirus EE 6.0
-
Computer Associates QO30577.CAZ
ftp://ftp.ca.com/CAproducts/unicenter/eTrust/AntiVirus/6.0/nt/qo30577/ QO30577.CAZ
References
Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability
References:
References:
- QO30577: NT-PRIVILEGE ELEVATION VULNERABILITY (Computer Associates)