what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

secres21122004-2.txt

secres21122004-2.txt
Posted Dec 31, 2004
Authored by Carsten Eiram | Site secunia.com

Secunia Research has discovered a vulnerability in Spy Sweeper Enterprise, which can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to the Spy Sweeper Enterprise Client SpySweeperTray.exe process invoking the help functionality with SYSTEM privileges. This can be exploited to execute arbitrary commands on a system with escalated privileges.

tags | advisory, arbitrary, local
SHA-256 | 0d382df0752cbac48c63a72e9a6d0b795444e664182c8248c9b7b2b8acb31c4e

secres21122004-2.txt

Change Mirror Download
====================================================================== 

Secunia Research 21/12/2004

- Spy Sweeper Enterprise Client Privilege Escalation Vulnerability -

======================================================================
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Vendor's Description of Software.....................................3
Description of Vulnerability.........................................4
Solution.............................................................5
Time Table...........................................................6
Credits..............................................................7
References...........................................................8
About Secunia........................................................9
Verification........................................................10

======================================================================
1) Affected Software

Spy Sweeper Enterprise 1.5.1 (Build 3698)

NOTE: Other versions may also be affected.

======================================================================
2) Severity

Rating: Less Critical
Impact: Privilege Escalation
Where: Local System

======================================================================
3) Vendor's Description of Software

Spy Sweeper Enterprise:
"Webroot Spy Sweeper Enterprise provides comprehensive spyware
protection for corporations. Using a client / server architecture,
Spy Sweeper Enterprise proactively detects and removes all forms of
spyware and malware within the organization".

Product link:
http://www.webroot.com/products/spysweeper/enterprise/

======================================================================
4) Description of Vulnerability

Secunia Research has discovered a vulnerability in Spy Sweeper
Enterprise, which can be exploited by malicious, local users to gain
escalated privileges.

The vulnerability is caused due to the Spy Sweeper Enterprise Client
"SpySweeperTray.exe" process invoking the help functionality with
SYSTEM privileges.

This can be exploited to execute arbitrary commands on a system with
escalated privileges.

======================================================================
5) Solution

The vendor has issued version 2.0, which fixes the vulnerability.

======================================================================
6) Time Table

15/11/2004 - Vulnerability discovered.
15/11/2004 - Vendor notified.
15/11/2004 - Vendor response.
19/12/2004 - Vendor issues version 2.0.
21/12/2004 - Public disclosure.

======================================================================
7) Credits

Discovered by Carsten Eiram, Secunia Research.

======================================================================
8) References

The Common Vulnerabilities and Exposures (CVE) project has not
currently assigned the vulnerability a candidate number.

======================================================================
9) About Secunia

Secunia collects, validates, assesses, and writes advisories regarding
all the latest software vulnerabilities disclosed to the public. These
advisories are gathered in a publicly available database at the
Secunia website:

http://secunia.com/

Secunia offers services to our customers enabling them to receive all
relevant vulnerability information to their specific system
configuration.

Secunia offers a FREE mailing list called Secunia Security Advisories:

http://secunia.com/secunia_security_advisories/

======================================================================
10) Verification

Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2004-14/

Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/

======================================================================

Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close