Symantec PCAnywhere Privilege Escalation Vulnerability
BID:9045
Info
Symantec PCAnywhere Privilege Escalation Vulnerability
| Bugtraq ID: | 9045 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0936 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 13 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery of this vulnerability has been credited to KF <[email protected]>. |
| Vulnerable: |
Symantec pcAnywhere 11.0 Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 |
| Not Vulnerable: | |
Discussion
Symantec PCAnywhere Privilege Escalation Vulnerability
Symantec pcAnywhere can be installed as a service that listens for incoming connections from a remote administrator. Local unprivileged users have the ability to exercise some levels of control over the pcAnywhere server via the pcAnywhere icon that is visible in the systray on a Windows system.
Symantec pcAnywhere has been reported prone to a vulnerability that will allow a local unprivileged user to elevate system privileges. The issue is likely related to the vulnerability described in BID 8884. It has been reported that any local user may elevate local privileges by exploiting functionality provided by pcAnywhere help.
Symantec pcAnywhere can be installed as a service that listens for incoming connections from a remote administrator. Local unprivileged users have the ability to exercise some levels of control over the pcAnywhere server via the pcAnywhere icon that is visible in the systray on a Windows system.
Symantec pcAnywhere has been reported prone to a vulnerability that will allow a local unprivileged user to elevate system privileges. The issue is likely related to the vulnerability described in BID 8884. It has been reported that any local user may elevate local privileges by exploiting functionality provided by pcAnywhere help.
Exploit / POC
Symantec PCAnywhere Privilege Escalation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Symantec PCAnywhere Privilege Escalation Vulnerability
Solution:
Symantec have strongly recommended customers of supported versions of pcAnywhere to update to the latest LiveUpdate packages in order to prevent exploitation of this vulnerability.
Solution:
Symantec have strongly recommended customers of supported versions of pcAnywhere to update to the latest LiveUpdate packages in order to prevent exploitation of this vulnerability.
References
Symantec PCAnywhere Privilege Escalation Vulnerability
References:
References: