CVE-2006-6308

Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability
Configurations

Configuration 1 (hide)

cpe:2.3:a:symantec:livestate_agent_for_windows:7.1:*:windows:*:*:*:*:*

History

07 Nov 2023, 01:59

Type Values Removed Values Added
Summary ** DISPUTED ** Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability. Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability

Information

Published : 2006-12-06 20:28

Updated : 2024-04-11 00:41


NVD link : CVE-2006-6308

Mitre link : CVE-2006-6308

CVE.ORG link : CVE-2006-6308


JSON object : View

Products Affected

symantec

  • livestate_agent_for_windows