Local Privilege Escalation in Symantec pcAnywhere 12.5
CVE-2006-3785
Currently unrated
Summary
Symantec pcAnywhere 12.5 contains a vulnerability where passwords are visually obfuscated in the user interface but remain unencrypted in the associated .cif (CallerID) file. This design flaw allows local users to extract these passwords using various software tools such as Nirsoft Asterwin. Attackers with local access to the system can exploit this oversight to gain unauthorized access to sensitive information.
References
Timeline
Vulnerability published
Vulnerability Reserved