First published: Tue Mar 26 2013(Updated: )
Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Enterprise Vault For File System Archiving | <=9.0.3 | |
Symantec Enterprise Vault For File System Archiving | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1609 has a medium severity rating as it allows local users to escalate privileges.
To fix CVE-2013-1609, upgrade to Symantec Enterprise Vault for File System Archiving version 9.0.4 or later, or version 10.0.1 or later.
CVE-2013-1609 affects Symantec Enterprise Vault for File System Archiving versions prior to 9.0.4 and 10.0.0.
The exploit method for CVE-2013-1609 involves using Trojan horse programs to gain privileged access through unquoted search paths.
No, CVE-2013-1609 can only be exploited locally by users with access to the vulnerable system.