CVE-2012-0304
22.06.2012, 10:24
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.Enginsight
Vendor | Product | Version |
---|---|---|
symantec | liveupdate_administrator | 𝑥 ≤ 2.3.0 |
symantec | liveupdate_administrator | 1.5.3.21 |
symantec | liveupdate_administrator | 1.5.4 |
symantec | liveupdate_administrator | 1.5.7.19 |
symantec | liveupdate_administrator | 2.1.0 |
symantec | liveupdate_administrator | 2.1.2 |
symantec | liveupdate_administrator | 2.1.3 |
symantec | liveupdate_administrator | 2.2.1 |
symantec | liveupdate_administrator | 2.2.2 |
symantec | liveupdate_administrator | 2.2.2.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References