CVE-2012-0304: Medium severity symantec liveupdate administrator vulnerability
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0304?
CVE-2012-0304 is considered to have a high severity due to weak permissions that can be exploited by local users.
What are the potential impacts of CVE-2012-0304?
CVE-2012-0304 allows local users to gain elevated privileges by manipulating files in a directory with weak permissions.
How do I fix CVE-2012-0304?
To fix CVE-2012-0304, adjust the permissions of the installation directory to restrict access to authorized users only.
Which software versions are affected by CVE-2012-0304?
CVE-2012-0304 affects various versions of Symantec LiveUpdate Administrator, including all versions prior to 2.3.1.
Is there a workaround for CVE-2012-0304?
A temporary workaround for CVE-2012-0304 is to limit local user access to the installation directory until a proper fix is applied.