PT-2006-4644 · Symantec · Pcanywhere
Root
·
Published
2006-07-21
·
Updated
2018-10-17
·
CVE-2006-3784
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec pcAnywhere version 12.5
Description
The issue allows local users to gain privileges by inserting a superuser .cif file into the "SymantecpcAnywhereHosts" folder, and then using a pcAnywhere client to login as a local administrator. This is due to weak default permissions for the folder.
Recommendations
For Symantec pcAnywhere version 12.5, consider changing the default permissions of the "SymantecpcAnywhereHosts" folder to prevent local users from inserting malicious .cif files. As a temporary workaround, restrict access to the folder and monitor for any suspicious activity.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pcanywhere