Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.
Link | Tags |
---|---|
http://secunia.com/advisories/14616/ | third party advisory vendor advisory |
http://marc.info/?l=bugtraq&m=111100364513513&w=2 | mailing list |
http://www.securityfocus.com/bid/12822 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19715 | vdb entry |