CVE-2007-5665: High severity Novell ZENworks Endpoint Security Management vulnerability
STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the diagnostic report directory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5665?
CVE-2007-5665 is considered a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2007-5665?
To fix CVE-2007-5665, update Novell ZENworks Endpoint Security Management to version 3.5.0.82 or later.
What are the potential impacts of exploiting CVE-2007-5665?
Exploiting CVE-2007-5665 allows local users to gain elevated privileges on affected systems.
Which versions of Novell ZENworks Endpoint Security Management are affected by CVE-2007-5665?
CVE-2007-5665 affects Novell ZENworks Endpoint Security Management versions up to 3.5.0.20.
Is CVE-2007-5665 a network or local vulnerability?
CVE-2007-5665 is a local vulnerability as it requires access to the system by an authenticated user.