Symantec LiveUpdate Administrator prior to 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
symantec liveupdate administrator |
||
symantec liveupdate administrator 1.5.3.21 |
||
symantec liveupdate administrator 1.5.4 |
||
symantec liveupdate administrator 1.5.7.19 |
||
symantec liveupdate administrator 2.1.0 |
||
symantec liveupdate administrator 2.1.2 |
||
symantec liveupdate administrator 2.1.3 |
||
symantec liveupdate administrator 2.2.1 |
||
symantec liveupdate administrator 2.2.2 |
||
symantec liveupdate administrator 2.2.2.9 |