CVE-2012-0304
Symantec LiveUpdate Administrator <2.3.1 - Privilege Escalation
Title source: llmDescription
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1027182
Various Sources x_refsource_misc
http://www.nessus.org/plugins/index.php?view=single&id=59193
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/53903
Vendor Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120615_00
Scores
EPSS
0.0004
EPSS Percentile
13.1%
Details
CWE
CWE-264
Status
published
Products (10)
symantec/liveupdate_administrator
1.5.3.21
symantec/liveupdate_administrator
1.5.4
symantec/liveupdate_administrator
1.5.7.19
symantec/liveupdate_administrator
2.1.0
symantec/liveupdate_administrator
2.1.2
symantec/liveupdate_administrator
2.1.3
symantec/liveupdate_administrator
2.2.1
symantec/liveupdate_administrator
2.2.2
symantec/liveupdate_administrator
2.2.2.9
symantec/liveupdate_administrator
< 2.3.0
Published
Jun 22, 2012
Tracked Since
Feb 18, 2026