Local Privilege Escalation in Symantec pcAnywhere 12.5
CVE-2006-3785

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
24 July 2006

Summary

Symantec pcAnywhere 12.5 contains a vulnerability where passwords are visually obfuscated in the user interface but remain unencrypted in the associated .cif (CallerID) file. This design flaw allows local users to extract these passwords using various software tools such as Nirsoft Asterwin. Attackers with local access to the system can exploit this oversight to gain unauthorized access to sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.