Privilege Escalation in Symantec AntiVirus and Norton Security for Macintosh
CVE-2007-5829
Currently unrated
Key Information:
- Vendor
Symantec
- Vendor
- CVE Published:
- 5 November 2007
What is CVE-2007-5829?
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, along with Norton AntiVirus for Macintosh 10.0 and 10.1 and Norton Internet Security for Macintosh 3.x, has a vulnerability that arises from its use of a directory with weak permissions, specifically group writable settings. This flaw permits local administrators to replace sensitive files, allowing them to execute arbitrary code with root privileges when a disk is mounted with the 'Show Progress During Mount Scans' option active. This scenario poses significant security risks, especially in environments where physical access to machines is possible.