CVE-2016-6590

A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
References
Link Resource
http://www.securityfocus.com/bid/94279 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037302 Third Party Advisory VDB Entry
https://support.symantec.com/us/en/article.symsa1385.html Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:encryption_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_encryption:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_encryption:7.6:*:*:*:*:*:*:*
cpe:2.3:a:symantec:ghost_solution_suite:3.1:-:*:*:*:*:*:*
cpe:2.3:a:symantec:ghost_solution_suite:3.1:maintenance_pack1:*:*:*:*:*:*
cpe:2.3:a:symantec:ghost_solution_suite:3.1:maintenance_pack2:*:*:*:*:*:*
cpe:2.3:a:symantec:ghost_solution_suite:3.1:maintenance_pack3:*:*:*:*:*:*
cpe:2.3:a:symantec:it_management_suite:7.6:*:*:*:*:*:*:*
cpe:2.3:a:symantec:it_management_suite:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-01-08 16:15

Updated : 2024-02-04 20:39


NVD link : CVE-2016-6590

Mitre link : CVE-2016-6590

CVE.ORG link : CVE-2016-6590


JSON object : View

Products Affected

symantec

  • it_management_suite
  • encryption_desktop
  • ghost_solution_suite
  • endpoint_encryption
CWE
CWE-269

Improper Privilege Management