CVE-2007-2279
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\VxSvc\CurrentVersion\Schedules specifying future command execution.
El Servicio Scheduler (VxSchedService.exe) en Symantec Storage Foundation para Windows versión 5.0 permite a los atacantes remotos omitir la autenticación y ejecutar código arbitrario por medio de ciertas peticiones al socket service que crea valores de registro (1) PreScript o (2) PostScript bajo Veritas\VxSvc CurrentVersion\Schedules , especificando una ejecución de comandos futura.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-04-26 CVE Reserved
- 2007-06-04 CVE Published
- 2024-04-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/36104 | Vdb Entry | |
http://seer.entsupport.symantec.com/docs/288627.htm | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/470562/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/24194 | Vdb Entry | |
http://www.securitytracker.com/id?1018188 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34680 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.symantec.com/avcenter/security/Content/2007.06.01.html | 2018-10-16 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25537 | 2018-10-16 | |
http://www.vupen.com/english/advisories/2007/2035 | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Symantec Search vendor "Symantec" | Veritas Storage Foundation Search vendor "Symantec" for product "Veritas Storage Foundation" | 5.0 Search vendor "Symantec" for product "Veritas Storage Foundation" and version "5.0" | windows |
Affected
|