Symantec Endpoint Protection Privilege Escalation Zero Day
The people at Offensive Security have announced that in the course of a penetration test for one of their customers they have found several vulnerabilities in the Symantec Endpoint Protection product. While details are limited, the vulnerabilities appear to permit privilege escalation to the SYSTEM user which would give virtually unimpeded access to the system. Offensive Security has posted a video showing the exploitation of one of the vulnerabilities.
Symantec has indicated they are aware of the vulnerabilities and are investigating.
There is some irony in the fact that there are Zero Day vulnerabilities in the software that a large portion of users count on to protect their computer from malware and software vulnerabilities. The fact is that software development is hard and even security software is not immune from exploitable vulnerabilities. If there is a bright side, it appears that there are no exploits in the wild yet and that local access to the machine is required to exploit these vulnerabilities.
-- Rick Wanner - rwanner at isc dot sans dot edu - http://namedeplume.blogspot.com/ - Twitter:namedeplume (Protected)
Comments
Anonymous
Jul 31st 2014
1 decade ago
Not really a nice thing in a large setup.
This KB is being updated, follow it.
http://www.symantec.com/docs/TECH223338
Anonymous
Aug 1st 2014
1 decade ago
See
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140804_00
Anonymous
Aug 5th 2014
1 decade ago
Anonymous
Aug 6th 2014
1 decade ago
Refer to this knowledge base article and all will be well.
http://www.symantec.com/business/support/index?page=content&id=TECH218029
Anonymous
Aug 8th 2014
1 decade ago