First published: Wed Apr 22 2015(Updated: )
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Workspace Streaming | =6.1-sp8 | |
Symantec Workspace Streaming | =7.5-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1484 is classified as a local privilege escalation vulnerability affecting Symantec Workspace Streaming.
To fix CVE-2015-1484, update Symantec Workspace Streaming to version 6.1 SP8 MP2 HF7 or 7.5 SP1 HF4 or later.
CVE-2015-1484 affects Symantec Workspace Streaming versions 6.1 SP8 before MP2 HF7 and 7.5 before SP1 HF4.
CVE-2015-1484 allows local users to gain elevated privileges by exploiting the unquoted Windows search path in the application.
CVE-2015-1484 requires local user access to exploit the vulnerability, making remote exploitation unlikely.