Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
BID:9052
Info
Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
| Bugtraq ID: | 9052 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2003 12:00AM |
| Updated: | Nov 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to D. Kalnæs. |
| Vulnerable: |
Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 Symantec pcAnywhere 9.2 Symantec pcAnywhere 9.0.1 |
| Not Vulnerable: |
Symantec pcAnywhere 11.0 |
Discussion
Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
Symantec pcAnywhere has been reported prone to a locally exploitable vulnerability when it has been configured to run in service mode. It has been reported that a local user or a user who has been granted interactive access to a system via pcAnywhere, may exploit an issue in the chat client to elevate privileges to that of the SYSTEM user.
It should be noted that this vulnerability affects Symantec pcAnywhere version 9.01 and 9.2 (which are unsupported). pcAnywhere 10.x is also affected.
Symantec pcAnywhere has been reported prone to a locally exploitable vulnerability when it has been configured to run in service mode. It has been reported that a local user or a user who has been granted interactive access to a system via pcAnywhere, may exploit an issue in the chat client to elevate privileges to that of the SYSTEM user.
It should be noted that this vulnerability affects Symantec pcAnywhere version 9.01 and 9.2 (which are unsupported). pcAnywhere 10.x is also affected.
Exploit / POC
Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
Solution:
Fixes for pcAnywhere 10.x may be obtained via LiveUpdate.
Solution:
Fixes for pcAnywhere 10.x may be obtained via LiveUpdate.
References
Symantec PCAnywhere Chat Client Privilege Escalation Vulnerability
References:
References:
- Symantec Homepage (Symantec)
- Symantec pcAnywhere Chat Mode Privilege Elevation (Symantec)
- Symantec pcAnywhere Homepage (Symantec)