First published: Tue Apr 12 2005(Updated: )
Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sygate Technologies | =3.5_build_2576 | |
Sygate Technologies | =3.5_build_2577 | |
Sygate Technologies | =4.0 | |
Sygate Technologies | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1103 has a medium severity rating due to its potential to allow unprivileged users to modify security policies.
To fix CVE-2005-1103, ensure that only privileged users have permission to update the security policy within Sygate Security Agent.
CVE-2005-1103 affects Sygate Security Agent versions 3.5 build 2576, 3.5 build 2577, 4.0, and 4.1.
Yes, local users can exploit CVE-2005-1103 by exporting the security policy, modifying it, and importing it back without proper restrictions.
CVE-2005-1103 is a local privilege escalation vulnerability in Sygate Secure Enterprise that allows unauthorized policy modifications.