Title : Novell ZENworks Endpoint Security Management Privilege Escalation VUPEN ID : VUPEN/ADV-2008-0044 CVE ID : CVE-2007-5665
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-01-07
Technical Description
A vulnerability has been identified in Novell ZENworks Endpoint Security Management (ESM), which could be exploited by local attackers to obtain elevated privileges. This issue is caused by an error in the STEngine service that generates diagnostic reports in an insecure manner, which could be exploited by malicious users to execute arbitrary code with SYSTEM privileges.