ZDI-25-693: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Norton Utilities Ultimate. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13944.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-693?
The severity of ZDI-25-693 is classified as high due to the potential for local privilege escalation.
How do I fix ZDI-25-693?
To fix ZDI-25-693, users should update Norton Utilities Ultimate to the latest version provided by the vendor.
Who is affected by ZDI-25-693?
ZDI-25-693 affects installations of Norton Utilities Ultimate that are vulnerable to local privilege escalation.
What type of attack does ZDI-25-693 enable?
ZDI-25-693 enables local attackers to escalate privileges on the affected system after executing low-privileged code.
What should I do if I cannot update Norton Utilities Ultimate to fix ZDI-25-693?
If you cannot update Norton Utilities Ultimate, you should limit access to the system and monitor for suspicious activities.