CVE-2012-0304

CWE-2643 documents3 sources
Severity
6.9MEDIUM
EPSS
0.0%
top 87.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 4

Description

Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cqgv-r6vr-mxr5: Symantec LiveUpdate Administrator before 22022-05-04
CVEList
CVE-2012-0304: Symantec LiveUpdate Administrator before 22012-06-22
CVE-2012-0304 (MEDIUM CVSS 6.9) | Symantec LiveUpdate Administrator b | cvebase.io