Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
2012-06-22T10:24:06.397
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | liveupdate_administrator | ≤ 2.3.0 | Yes |
Application | symantec | liveupdate_administrator | 1.5.3.21 | Yes |
Application | symantec | liveupdate_administrator | 1.5.4 | Yes |
Application | symantec | liveupdate_administrator | 1.5.7.19 | Yes |
Application | symantec | liveupdate_administrator | 2.1.0 | Yes |
Application | symantec | liveupdate_administrator | 2.1.2 | Yes |
Application | symantec | liveupdate_administrator | 2.1.3 | Yes |
Application | symantec | liveupdate_administrator | 2.2.1 | Yes |
Application | symantec | liveupdate_administrator | 2.2.2 | Yes |
Application | symantec | liveupdate_administrator | 2.2.2.9 | Yes |