>> Symantec and Norton AntiVirus for Macintosh Privilege Escalation Issue
Title : Symantec and Norton AntiVirus for Macintosh Privilege Escalation Issue VUPEN ID : VUPEN/ADV-2007-3698 CVE ID : CVE-2007-5829
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-11-02
Technical Description
A vulnerability has been identified in various Symantec products for Macintosh, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by insecure permissions being set on the "/Library/Application Support" directory, which could be exploited by malicious members of the group admin to replace an executable used by the Mount Scan feature by a malicious binary and execute arbitrary code with root privileges.
Note : This vulnerability exists only when the Mount Scanning feature enabled and configured to show the progress.