First published: Tue May 01 2012(Updated: )
Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Shared directory, which allows local users to gain privileges via a Trojan horse file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Toad for Data Analysts | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0279 is categorized as a medium severity vulnerability due to weak permissions allowing local users to gain unauthorized privileges.
To fix CVE-2012-0279, you should change the permissions of the %COMMONPROGRAMFILES%\Quest Shared directory to restrict access to trusted users only.
The potential impacts of CVE-2012-0279 include unauthorized privilege escalation, allowing local users to execute malicious files.
CVE-2012-0279 affects users of Quest Toad for Data Analysts version 3.0.1 installed on systems with weak directory permissions.
CVE-2012-0279 is not exploitable remotely, as it requires local access to the affected system.