CVE-2012-0304
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
22/06/2012
Last modified:
11/04/2025
Description
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:symantec:liveupdate_administrator:*:*:*:*:*:*:*:* | 2.3.0 (including) | |
| cpe:2.3:a:symantec:liveupdate_administrator:1.5.3.21:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:1.5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:1.5.7.19:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:liveupdate_administrator:2.2.2.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.nessus.org/plugins/index.php?view=single&id=59193
- http://www.securityfocus.com/bid/53903
- http://www.securitytracker.com/id?1027182=
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120615_00
- http://www.nessus.org/plugins/index.php?view=single&id=59193
- http://www.securityfocus.com/bid/53903
- http://www.securitytracker.com/id?1027182=
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120615_00



