First published: Mon Jul 23 2012(Updated: )
Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Backup Exec System Recovery | =2010 | |
Symantec Backup Exec System Recovery | =2011 | |
Symantec System Recovery 2011 | =2011 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0305 describes an untrusted search path vulnerability that allows local users to gain elevated privileges via a Trojan horse DLL.
CVE-2012-0305 affects Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5.
To mitigate CVE-2012-0305, ensure that you update to the latest service packs for the affected Symantec software.
If exploited, CVE-2012-0305 could allow local users to execute arbitrary code with elevated privileges.
Yes, Symantec has released updates that address CVE-2012-0305, which should be applied promptly.