TITLE: Symantec pcAnywhere CIF Files Privilege Escalation
SECUNIA ADVISORY ID: SA21113
VERIFY ADVISORY: http://secunia.com/advisories/21113/
CRITICAL: Less critical
IMPACT: Privilege escalation
WHERE: Local system
SOFTWARE: Symantec pcAnywhere 12.x
http://secunia.com/product/11089/
DESCRIPTION: Zee has reported a security issue in Symantec pcAnywhere, which can be exploited by malicious, local users to gain escalated privileges. The problem is caused due to CIF files containing a superuser flag and being stored insecurely by default in "Documents and SettingsAll UsersApplication DataSymantecpcAnywhereHosts" where any user can read the contents of files and create new files. This can be exploited to gain administrative user privileges via pcAnywhere by crafting a new CIF file, setting the superuser flag, and placing the file in the "Hosts" directory.
The security issue has been reported in version 12.5. Other versions may also be affected.
SOLUTION: Grant only trusted users access to affected systems.
PROVIDED AND/OR DISCOVERED BY: Zee
ORIGINAL ADVISORY: http://www.digitalbullets.org/?p=3
Symantec pcAnywhere CIF Files Privilege EscalationPosted on Wednesday, July 19, 2006 @ 09:45:51 CDT in Security |