Skip to main content

Symantec pcAnywhere / IT Management Suite Multiple Vulnerabilities

Last Update Date: 26 Jan 2012 12:27 Release Date: 26 Jan 2012 4525 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Symantec pcAnywhere and IT Management Suite, which can be exploited by malicious, local users to perform certain actions with escalated privileged and by malicious people to compromise a vulnerable system.

  1. Insecure file permissions on certain files, which can be exploited to overwrite the files and gain escalated privileges.
  2. An input validation error within the login and authentication mechanism in host services. Successful exploitation of this vulnerability may allow execution of arbitrary code.
     

Impact

  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Symantec Altiris IT Management Suite 7.x
  • Symantec pcAnywhere 12.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply hotfix TECH179526.

Vulnerability Identifier


Source


Related Link