First published: Tue Nov 18 2003(Updated: )
Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec pcAnywhere | =10.0 | |
Symantec pcAnywhere | =11.0 | |
Symantec pcAnywhere | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0936 is classified as a high severity vulnerability due to the potential for attackers to gain SYSTEM privileges.
To fix CVE-2003-0936, it is recommended to disable the affected service or upgrade to a later, patched version of Symantec pcAnywhere.
CVE-2003-0936 affects Symantec pcAnywhere versions 10.0, 10.5, and 11.0.
CVE-2003-0936 allows attackers to exploit the help interface of AWHOST32.exe when it is running as a service.
As a mitigative measure for CVE-2003-0936, consider running the application with the least privileges required to limit potential damage.