Symantec LiveState Lets Local Users Gain System Privileges
|
|
SecurityTracker Alert ID: 1017332
|
|
SecurityTracker URL: http://securitytracker.com/id?1017332
|
|
CVE Reference: CVE-2006-6308
(Links to External Site)
|
Updated: May 22 2008
|
Original Entry Date: Dec 5 2006
|
Impact: Execution of arbitrary code via local system, Root access via local system
|
Exploit Included: Yes
|
Version(s): 7.1 (Agent)
|
Description: A vulnerability was reported in Symantec LiveState. A local user can obtain system privileges on the target system.
A local user can stop the 'shstart.exe' process and run the "Web Self-Service" feature from the LiveState agent icon in the Windows
system tray. The resulting browser window will be executed with System privileges.
marc & shb reported this vulnerability.
[Editor's
note: Several users have noted that system or administrator privileges are required to stop the 'shstart.exe' process. In that
case, the reported behavior does not allow a local user to obtain any greater privileges than they would already have.]
|
Impact: A local user can obtain System privileges on the target system.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.symantec.com/ (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Windows (Any)
|
Reported By: ss_team <ssteam.pl@gmail.com>
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 4 Dec 2006 17:28:05 +0100
From: ss_team <ssteam.pl@gmail.com>
Subject: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation
|
hello,
we've found local privilege escalation in Symantec LiveState agent.
PoC:
1. kill shstart.exe process
2. from symantec livestate agent icon in systray choose "Web Self-Service"
3. New browser window will open, it is running with SYSTEM privileges.
tested on fully patched Win XP SP2, Symantec LiveState agent 7.1
Credits: marc & shb
--
http://ssteam.ath.cx
|
|