Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Symantec Automatic LiveUpdate Local User Elevation of Privilege

Thread Tools
 
Search this Thread
 
Old 13 January 2004, 04:40 PM
  #1  
Nicks VR4
Scooby Regular
Thread Starter
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Post

Anyone using this might want to update there liveupdate version

http://www.sarc.com/avcenter/securit...004.01.12.html

SYM04-001
January 12, 2004
Symantec Automatic LiveUpdate Local User Elevation of Privilege
Revision History
None

Risk Impact
Medium

Local access required. Automatic LiveUpdate launches as a scheduled task if so configured and only on systems running retail versions of Symantec products. Impact of this issue would result in elevated privilege on the host system only and is highly dependent on system configuration and environment.

Overview
Security analysts from Secure Network Operations notified Symantec of a potential issue with the Automatic LiveUpdate feature, available with retail versions of some Symantec products, when running as a scheduled task. If the system is configured as a multi-user system with privileged and non-privileged user access, a non-privileged user could potentially access and manipulate the Symantec Automatic LiveUpdate GUI functionality to gain privileged system access.

Affected Components
Symantec Windows LiveUpdate 1.70.x through 1.90.x
Symantec Norton SystemWorks 2001-2004
Symantec Norton AntiVirus and Norton AntiVirus Pro 2001-2004
Symantec Norton Internet Security and Norton Internet Security Pro 2001-2004
Symantec AntiVirus for Handhelds v3.0


Not Affected
Symantec Windows LiveUpdate v2.x
Symantec Java LiveUpdate (all versions)
Symantec Enterprise products (Symantec Enterprise products do not support the Automatic LiveUpdate functionality)


Details
Symantec Automatic LiveUpdate, a functionality included with many Symantec retail products, is launched by the system scheduler on system startup and then periodically after startup. Symantec Automatic LiveUpdate checks for available updates to any supported Symantec products installed on the system.

Symantec Automatic LiveUpdate can be configured to notify the user when Symantec product updates are available for download. Symantec Automatic LiveUpdate does this via a LiveUpdate icon displayed in the system taskbar. At this prompt, the user may choose to open an interactive LiveUpdate session to retrieve any available updates.

When a vulnerable version of Symantec Automatic LiveUpdate is initially launched at startup it is assigned Local System privileges. During the time when an interactive LiveUpdate session is available, and only during this session, a non-privileged user could potentially manipulate the LiveUpdate GUI functionality to gain elevated privilege on the local host. For example, the user could gain privileges to search all system files, assume full permission for directories and files on the host, or add themselves to the local administrative group.

Symantec Response
Symantec verified this vulnerability does exist in the current supported versions of Automatic LiveUpdate shipped with many Symantec retail products. This issue is fixed in the latest release of Symantec Windows LiveUpdate v2.0.

Symantec Windows LiveUpdate 2.0 is available for download from the Symantec technical support site at http://www.symantec.com/techsupp/files/lu/lu.html should you choose not to update via Symantec's LiveUpdate capability.

Symantec Windows LiveUpdate 2.0 is also available for all supported Symantec products via the Symantec product's LiveUpdate function. To update using LiveUpdate, select the LiveUpdate option within your retail Symantec product and download and install all available updates. In some cases, the update to LiveUpdate 2.0 may required a restart of your system to complete.

To determine your version of Symantec LiveUpdate:

Open any Symantec retail product installed on your system, e.g., Symantec Norton AntiVirus 2004
Click on LiveUpdate in the toolbar
Click on the LiveUpdate system menu to see the drop-down selections
Click on "About LiveUpdate" to see the version of LiveUpdate you are running
If you are running a version of Symantec LiveUpdate prior to v2.0, Symantec recommends running LiveUpdate or downloading Symantec Windows LiveUpdate v2.0 from the support site indicated above to upgrade your system to the latest version of Symantec LiveUpdate.

Mitigating Circumstances
While effectively exploiting this issue would permit a non-privileged user to gain privileged access on the local host, there are mitigating circumstances that greatly reduce the risk of exploitation in Symantec's Automatic LiveUpdate:

Symantec Automatic LiveUpdate is implemented in retail versions of Symantec products ONLY.


The system is vulnerable only if the interactive LiveUpdate capability is available to the user


Automatic LiveUpdate must be configured with the option enabled to notify the user when updates are available


If the system is a single-user system, this issue would not have an impact


If the system IS configured as a multi-user system with privileged and non-privileged user access to the host system, the non-privileged user would require an authorized user account on the host system and must be logged on interactively to exploit this issue


Elevated privileges can be gained only on the local system, which normally limits any impact


Credit
Symantec takes the security and proper functionality of its products very seriously. Symantec appreciates the efforts of KF and the Security Network Operations security team in identifying this issue and coordinating with Symantec during the verification and fix process to properly update and protect Symantec customers. Information on this and other security issues can be found at the Secure Network Operations Inc. web site, http://www.secnetops.com/

CVE

Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
02 July 2023 01:54 PM
shorty87
Full Cars Breaking For Spares
19
22 December 2015 11:59 AM
Pro-Line Motorsport
Car Parts For Sale
2
29 September 2015 07:36 PM
shorty87
Wheels And Tyres For Sale
0
29 September 2015 02:18 PM
shorty87
Other Marques
0
25 September 2015 08:52 PM



Quick Reply: Symantec Automatic LiveUpdate Local User Elevation of Privilege



All times are GMT +1. The time now is 06:37 PM.