Release date:
Updated on:
Affected Systems:
Symantec Enterprise Security Manager 9.0.325
Symantec Enterprise Security Manager 6.5.3
Symantec Enterprise Security Manager 6.5.2
Symantec Enterprise Security Manager 6.5.1
Symantec Enterprise Security Manager 6.5
Symantec Enterprise Security Manager 6.0
Symantec Enterprise Security Manager 10.0.274
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56915
CVE (CAN) ID: CVE-2012-4350
Symantec Enterprise Security Manager (ESM) can automatically search for critical applications and servers throughout the Enterprise to discover vulnerabilities and settings that do not comply with Security policies.
Symantec's Enterprise Security Manager (ESM) for Windows has an unreferenced search path in the Manager and Agent components. If Unauthorized Local Users can insert arbitrary code into the root path, you can execute the code when the system is started or restarted.
<* Source: Gavin Jones
Link: http://www.securitytracker.com/id/1027874
Http://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = secu
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Symantec
--------
Symantec has released a Security Bulletin (20121213_00) for this purpose and the corresponding patch:
20121213_00: Security Advisories Relating to Symantec Products-Symantec Enterprise Security Manager/Agent Local Elevation of Privilege
Link: http://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = secu
Patch download: https://www.symantec.com/security_response/securityupdates/list.jsp? Fid = esm & pvid = pu