5
CVSSv2

CVE-2012-0292

Published: 08/03/2012 Updated: 06/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The awhost32 service in Symantec pcAnywhere up to and including 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote malicious users to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec pcanywhere 12.5.265

symantec pcanywhere 12.0

symantec pcanywhere 10.5

symantec pcanywhere 12.0.1

symantec pcanywhere 12.0.2

symantec pcanywhere 12.5.539

symantec pcanywhere 12.5

symantec pcanywhere 11.0.1

symantec pcanywhere 11.5

symantec pcanywhere

symantec pcanywhere 10.0

symantec pcanywhere 11.5.1

symantec pcanywhere 12.5.3

symantec pcanywhere 12.1

symantec pcanywhere 12.0.3

symantec pcanywhere 11.0

symantec altiris it management suite pcanywhere solution 7.0

symantec altiris it management suite pcanywhere solution 7.1

symantec altiris climentent manage suite pcanywhere solution 7.1

symantec altiris client management suite pcanywhere solution 7.0

symantec altiris deployment solution remote pcanywhere solution 7.1

Exploits

#!/usr/bin/python ''' Exploit Title: PCAnywhere Nuke Date: 2/16/12 Author: Johnathan Norman spoofy <at> exploitscienceorg or @spoofyroot Version: PCAnyWhere (1250 build 463) and below Tested on: Windows Description: The following code will crash the awhost32 service It'll be respawned so if you want to be a real pain you'll need t ...