My Firewall Plus Help Function Lets Local Users Gain System Privileges
Categorie: Vulnerability Posted: 2004-12-23 by ReCall Views: 420 Source: Click here
Current Rating: Not rated
Details
Description: A vulnerability was reported in My Firewall Plus. A local user can gain elevated privileges.
Secunia Research reported that the 'smc.exe' process runs the help function with System privileges. A local user can exploit the help function to execute arbitrary code with System level privileges.
The vendor was notified on November 15, 2004.
Carsten Eiram of Secunia Research discovered this flaw.
Impact: A local user can execute arbitrary code with System level privileges.