Symantec LiveState Lets Local Users Gain System Privileges
|
SecurityTracker Alert ID: 1017332 |
SecurityTracker URL: http://securitytracker.com/id/1017332
|
CVE Reference:
CVE-2006-6308
(Links to External Site)
|
Updated: May 22 2008
|
Original Entry Date: Dec 5 2006
|
Impact:
Execution of arbitrary code via local system, Root access via local system
|
Exploit Included: Yes
|
Version(s): 7.1 (Agent)
|
Description:
A vulnerability was reported in Symantec LiveState. A local user can obtain system privileges on the target system.
A local user can stop the 'shstart.exe' process and run the "Web Self-Service" feature from the LiveState agent icon in the Windows system tray. The resulting browser window will be executed with System privileges.
marc & shb reported this vulnerability.
[Editor's note: Several users have noted that system or administrator privileges are required to stop the 'shstart.exe' process. In that case, the reported behavior does not allow a local user to obtain any greater privileges than they would already have.]
|
Impact:
A local user can obtain System privileges on the target system.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: www.symantec.com/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Subject: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation
|
hello,
we've found local privilege escalation in Symantec LiveState agent.
PoC:
1. kill shstart.exe process
2. from symantec livestate agent icon in systray choose "Web Self-Service"
3. New browser window will open, it is running with SYSTEM privileges.
tested on fully patched Win XP SP2, Symantec LiveState agent 7.1
Credits: marc & shb
--
http://ssteam.ath.cx
|
|