CVE-2005-1970: High severity symantec pcanywhere vulnerability
Published Jun 14, 2005
·Updated
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.
Affected Software
8 affected components
Symantec pcAnywhere=8.0.1
Symantec pcAnywhere=8.0.2
Symantec pcAnywhere=9.0
Symantec pcAnywhere=9.0.1
Symantec pcAnywhere=9.2
Symantec pcAnywhere=10.0
Symantec pcAnywhere=10.5
Symantec pcAnywhere=11.0
Remediation
Patch Available
Event History
Jun 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1970?
CVE-2005-1970 is considered a moderate severity vulnerability allowing local users to execute arbitrary commands.
2
How do I fix CVE-2005-1970?
To fix CVE-2005-1970, you should upgrade Symantec pcAnywhere to version 11.5 or later.
3
Which versions of Symantec pcAnywhere are affected by CVE-2005-1970?
CVE-2005-1970 affects Symantec pcAnywhere versions 10.5 and earlier, including 9.0, 9.1, 9.2, and 11.0.
4
Can physical access allow exploitation of CVE-2005-1970?
Yes, physical access is required for a local user to exploit CVE-2005-1970 by using the Caller Properties feature.
5
What type of commands can be executed due to CVE-2005-1970?
Due to CVE-2005-1970, local users can execute arbitrary commands on the affected system.