Computer Security


Symantec PCAnywhere multiple security vulnerabilities
updated since 30.01.2012
SecurityVulns ID:12163
Threat Level:
Description:Code execution, privilege escalation.
Affected:SYMANTEC : pcAnywhere 12.5
 SYMANTEC : IT Management Suite 7.0
 SYMANTEC : IT Management Suite 7.1
CVE:CVE-2011-3478 (The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.)
Original documentdocumentResearch@NGSSecure, NGS00117 Technical Advisory: Symantec pcAnywhere insecure file permissions local privilege escalation (01.05.2012)
 documentResearch@NGSSecure, NGS00118 Technical Advisory: Symantec pcAnywhere Remote Code Execution as SYSTEM (01.05.2012)
 documentResearch@NGSSecure, ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability (30.01.2012)
 documentResearch@NGSSecure, NGS00117 Patch Notification: Symantec PCAnywhere Local Privilege Escalation (30.01.2012)
 documentResearch@NGSSecure, NGS00118 Patch Notification: Symantec PCAnywhere Remote Code Execution as SYSTEM (30.01.2012)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod