CVE-2012-0304

Symantec LiveUpdate Administrator <2.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027182
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53903

Scores

EPSS 0.0004
EPSS Percentile 13.1%

Details

CWE
CWE-264
Status published
Products (10)
symantec/liveupdate_administrator 1.5.3.21
symantec/liveupdate_administrator 1.5.4
symantec/liveupdate_administrator 1.5.7.19
symantec/liveupdate_administrator 2.1.0
symantec/liveupdate_administrator 2.1.2
symantec/liveupdate_administrator 2.1.3
symantec/liveupdate_administrator 2.2.1
symantec/liveupdate_administrator 2.2.2
symantec/liveupdate_administrator 2.2.2.9
symantec/liveupdate_administrator < 2.3.0
Published Jun 22, 2012
Tracked Since Feb 18, 2026