First published: Fri May 11 2007(Updated: )
Symantec pcAnywhere 11.5.x and 12.0.x retains unencrypted login credentials for the most recent login within process memory, which allows local administrators to obtain the credentials by reading process memory, a different vulnerability than CVE-2006-3785.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec pcAnywhere | =11.5 | |
Symantec pcAnywhere | =12.0 | |
Symantec pcAnywhere | =11.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2619 is classified as a high severity vulnerability due to its potential to expose sensitive login credentials.
To fix CVE-2007-2619, users should upgrade to a version of Symantec pcAnywhere that is not affected, such as any version beyond 12.0.x.
CVE-2007-2619 allows local administrators to read process memory and obtain unencrypted login credentials, leading to unauthorized access.
Symantec pcAnywhere versions 11.5.x and 12.0.x are affected by CVE-2007-2619.
Disabling remote access features may help mitigate the risk associated with CVE-2007-2619 if an immediate upgrade cannot be performed.