Symantec pcAnywhere CIF Files Privilege Escalation

Affected Software: Symantec pcAnywhere 12.x
Zee has reported a security issue in Symantec pcAnywhere, which can be exploited by malicious, local users to gain escalated privileges.

The problem is caused due to CIF files containing a superuser flag and being stored insecurely by default in “Documents and SettingsAll UsersApplication DataSymantecpcAnywhereHosts” where any user can read the contents of files and create new files. This can be exploited to gain administrative user privileges via pcAnywhere by crafting a new CIF file, setting the superuser flag, and placing the file in the “Hosts” directory.

The security issue has been reported in version 12.5. Other versions may also be affected.

Solution: Grant only trusted users access to affected systems.

Leave a Reply