Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
BID:66399
Info
Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
| Bugtraq ID: | 66399 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-1644 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2014 12:00AM |
| Updated: | Apr 02 2014 01:06AM |
| Credit: | Stefan Viehböck of SEC Consult Vulnerability Lab. |
| Vulnerable: |
Symantec LiveUpdate Administrator 2.3 Symantec LiveUpdate Administrator 2.2.2.9 |
| Not Vulnerable: | |
Discussion
Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
Symantec LiveUpdate Administrator is prone to an unauthorized-access vulnerability.
Successful exploits will allow attackers to gain unauthorized access to reset the password of other users. This may aid in further attacks.
Symantec LiveUpdate Administrator 2.3.2 and prior are vulnerable.
Symantec LiveUpdate Administrator is prone to an unauthorized-access vulnerability.
Successful exploits will allow attackers to gain unauthorized access to reset the password of other users. This may aid in further attacks.
Symantec LiveUpdate Administrator 2.3.2 and prior are vulnerable.
Exploit / POC
Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec LiveUpdate Administrator CVE-2014-1644 Unauthorized Access Vulnerability
References:
References:
- Symantec Home Page (Symantec)