CVE-2003-0936: High severity symantec pcanywhere vulnerability
Published Nov 18, 2003
·Updated
Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.
Affected Software
3 affected components
Symantec pcAnywhere=10.0
Symantec pcAnywhere=10.5
Symantec pcAnywhere=11.0
Remediation
Event History
Nov 18, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 15, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0936?
CVE-2003-0936 is classified as a high severity vulnerability due to the potential for attackers to gain SYSTEM privileges.
2
How do I fix CVE-2003-0936?
To fix CVE-2003-0936, it is recommended to disable the affected service or upgrade to a later, patched version of Symantec pcAnywhere.
3
Which versions of Symantec pcAnywhere are affected by CVE-2003-0936?
CVE-2003-0936 affects Symantec pcAnywhere versions 10.0, 10.5, and 11.0.
4
How does CVE-2003-0936 allow attackers to gain SYSTEM privileges?
CVE-2003-0936 allows attackers to exploit the help interface of AWHOST32.exe when it is running as a service.
5
Is there a mitigative measure I can take for CVE-2003-0936?
As a mitigative measure for CVE-2003-0936, consider running the application with the least privileges required to limit potential damage.