Title : PGP Desktop PGPServ/PGPsdkServ Objects Handling Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0356 CVE ID : CVE-2007-0603
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-26
Technical Description
A vulnerability has been identified in PGP Desktop, which could be exploited by malicious users to obtain elevated privileges. This issue is due to an error in the PGPServ/PGPsdkServ service when handling specially crafted objects passed over the RPC interface, which could be exploited by authenticated attackers to execute arbitrary commands with SYSTEM privileges.