CVE-2007-5829

Symantec AntiVirus for Macintosh <10.x - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018890
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38229
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27488
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26253
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018889
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3698
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/40864

Scores

EPSS 0.0005
EPSS Percentile 15.3%

Details

CWE
CWE-264
Status published
Products (7)
symantec/norton_antivirus 9.0
symantec/norton_antivirus 9.0.1
symantec/norton_antivirus 9.0.2
symantec/norton_antivirus 9.0.3
symantec/norton_antivirus 10.0
symantec/norton_antivirus 10.1
symantec/norton_internet_security 3.0
Published Nov 05, 2007
Tracked Since Feb 18, 2026