Lucene search

K
cveMitreCVE-2006-6308
HistoryDec 06, 2006 - 8:28 p.m.

CVE-2006-6308

2006-12-0620:28:00
mitre
web.nvd.nist.gov
34
symantec
livestate
agent
windows
privilege escalation
vulnerability
cve-2006-6308
nvd

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.6%

Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open “Web Self-Service” from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability

Affected configurations

Nvd
Node
symanteclivestate_agent_for_windowsMatch7.1windows
VendorProductVersionCPE
symanteclivestate_agent_for_windows7.1cpe:2.3:a:symantec:livestate_agent_for_windows:7.1:*:windows:*:*:*:*:*

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for CVE-2006-6308