Local Privilege Escalation in Symantec pcAnywhere 12.5
CVE-2006-3784
Currently unrated
What is CVE-2006-3784?
Symantec pcAnywhere 12.5 contains a vulnerability due to inadequate permissions for the 'Symantec\pcAnywhere\Hosts' directory. This misconfiguration allows local users to escalate their privileges by placing a specially crafted superuser .cif file within the folder. Once the file is in place, the user can exploit this flaw by logging into pcAnywhere as a local administrator, potentially compromising system integrity and exposing sensitive information.