Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
BID:72308
Info
Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
| Bugtraq ID: | 72308 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7288 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2015 12:00AM |
| Updated: | Jan 29 2015 12:00AM |
| Credit: | Paul Craig, withVantagePoint. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
Symantec Encryption Management Server is prone to a local command-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with elevated privileges.
The following products and versions are vulnerable:
Versions prior to Symantec Encryption Management Server 3.3.2 MP6
Versions prior to Symantec PGP Universal Server 3.3.2 MP6
Symantec Encryption Management Server is prone to a local command-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with elevated privileges.
The following products and versions are vulnerable:
Versions prior to Symantec Encryption Management Server 3.3.2 MP6
Versions prior to Symantec PGP Universal Server 3.3.2 MP6
Exploit / POC
Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Encryption Management Server CVE-2014-7288 Local Command Injection Vulnerability
References:
References:
- Symantec Homepage (Symantec)