Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Symantec LiveUpdate Local Privilege Escalation Vulnerability

Symantec LiveUpdate has been reported prone to a local privilege escalation vulnerability. This issue presents itself when a LiveUpdate interactive session is created. The privileges of the process, if different from the user, are not lowered. This may allow a local attacker to employ the vulnerable LiveUpdate component to spawn arbitrary executables with the privileges of the LiveUpdate process.







 

Privacy Statement
Copyright 2008, SecurityFocus