2023-11-07 21:03:21 +00:00

103 lines
3.5 KiB
JSON

{
"id": "CVE-2006-6308",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-12-06T20:28:00.000",
"lastModified": "2023-11-07T01:59:50.133",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open \"Web Self-Service\" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability"
},
{
"lang": "es",
"value": "** IMPUGNADA ** Symantec LiveState 7.1 Agent para Windows permite a usuarios locales obtener privilegios parando el proceso shstart.exe y abriendo \"Web Self-Service\" de la barra de iconos del sistema, lo cual abrir\u00e1 una ventana de navegaci\u00f3n ejecut\u00e1ndose con privilegios elevados. NOTA: varios investigadores de terceras partes han observado que podr\u00edan ser necesarios privilegios de administrador para terminar el proceso shstart.exe. Si este fuera el caso, entonces no ocurrir\u00eda la escalada de privilegios, y eso no es una vulnerabilidad."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.1,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:livestate_agent_for_windows:7.1:*:windows:*:*:*:*:*",
"matchCriteriaId": "0898446C-95D1-40C3-8B88-50A496BB5214"
}
]
}
]
}
],
"references": [
{
"url": "http://securitytracker.com/id?1017332",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453481/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453551/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453569/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453587/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453653/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30728",
"source": "cve@mitre.org"
}
]
}