#VU44364 Permissions, Privileges, and Access Controls in pcAnywhere - CVE-2011-3479
Published: January 25, 2012 / Updated: August 11, 2020
pcAnywhere
Broadcom
Description
The vulnerability allows a local #AU# to execute arbitrary code.
Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable permissions for product-installation files, which allows local users to gain privileges by modifying a file.