Lucene search

K
cveSymantecCVE-2013-1609
HistoryMar 26, 2013 - 2:07 p.m.

CVE-2013-1609

2013-03-2614:07:27
symantec
web.nvd.nist.gov
122
symantec
enterprise vault
ev
file system archiving
cve-2013-1609
windows
vulnerabilities
search path
local users
privileges
trojan horse program
nvd

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

AI Score

9

Confidence

High

EPSS

0

Percentile

9.5%

Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.

Affected configurations

Nvd
Node
symantecenterprise_vault_for_file_system_archivingRange9.0.3
OR
symantecenterprise_vault_for_file_system_archivingMatch10.0.0
VendorProductVersionCPE
symantecenterprise_vault_for_file_system_archiving*cpe:2.3:a:symantec:enterprise_vault_for_file_system_archiving:*:*:*:*:*:*:*:*
symantecenterprise_vault_for_file_system_archiving10.0.0cpe:2.3:a:symantec:enterprise_vault_for_file_system_archiving:10.0.0:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

AI Score

9

Confidence

High

EPSS

0

Percentile

9.5%

Related for CVE-2013-1609