PT-2012-1710 · Symantec · Pcanywhere+1

Published

2012-01-25

·

Updated

2018-01-06

·

CVE-2011-3479

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec pcAnywhere versions 12.5.x through 12.5.3 Symantec IT Management Suite pcAnywhere Solution version 7.0 (aka 12.5.x) Symantec IT Management Suite pcAnywhere Solution version 7.1 (aka 12.6.x)
Description The issue allows local users to gain privileges by modifying a file due to world-writable permissions for product-installation files.
Recommendations For Symantec pcAnywhere versions 12.5.x through 12.5.3, consider changing the permissions of the product-installation files to prevent world-writable access until a patch is available. For Symantec IT Management Suite pcAnywhere Solution version 7.0 (aka 12.5.x), restrict access to the installation files to minimize the risk of exploitation. For Symantec IT Management Suite pcAnywhere Solution version 7.1 (aka 12.6.x), apply configuration changes to limit the permissions of the installation files.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3479

Affected Products

It Management Suite Pcanywhere Solution
Pcanywhere