Symantec pcAnywhere provides the option to run user defined commands when the remote host is connected. Enabling the “Launch with Windows” from the Host Properties Settings tab configures the pcAnyware host to run as a service with Local System privileges. A non-privileged user with physical access to the system can potentially manipulate the Caller Properties feature to run arbitrary commands that will be executed with system level privileges when the system is restarted. This could potentially allow them to gain unauthorized Local System privilege on the targeted system.
Symantec has released a patch to address this issue. The patch can be downloaded from the Symantec technical support site. This patch ensures all commands launched through "Command to execute after connection" are launched within the scope of the logged in user’s access rights.
Symantec is not aware of any active attempts against or organizations impacted by this issue.
Affected Products (Consumer and Enterprise versions)
Symantec pcAnywhere All unsupported versions prior to 10.5x
Symantec pcAnywhere version 10.5x
Symantec pcAnywhere version 11x
Products Not Affected
Symantec pcAnywhere 11.5
Only Symantec products indicated above are potentially vulnerable. All other Symantec products are NOT affected.
Patches for this issue can be downloaded from the following locations:
For consumer versions of Symantec pcAnywhere:
For enterprise versions of Symantec pcAnywhere:
Select your supported version of Symantec pcAnywhere and follow the instructions to download the appropriate update.
As a part of normal best practices, users should keep vendor-supplied patches for all application software and operating systems up-to-date. Symantec strongly recommends any affected customers update their product immediately to protect against these types of threats.
Symantec takes the security and proper functionality of our products very seriously. As founding members of the Organization for Internet Safety (OISafety), Symantec supports and follows the principles of responsible disclosure. Symantec also subscribes to the vulnerability disclosure guidelines outlined by the National Infrastructure Advisory Council (NIAC).
Please contact firstname.lastname@example.org if you feel you have discovered a security issue in a Symantec product. A Symantec Product Security team member will contact you regarding your submission. Symantec strongly recommends using encrypted email for reporting vulnerability information to email@example.com. The Symantec Product Security PGP key can be found at the end of this message.
Symantec has developed a Product Vulnerability Response document outlining the process we follow in addressing suspected vulnerabilities in our products. This document is available below.
Copyright (c) 2009 by Symantec Corp.
Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Security Response. Reprinting the whole or part of this alert in any medium other than electronically requires permission from firstname.lastname@example.org.
The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.
Symantec, Symantec products, Symantec Security Response, and email@example.com are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.
Initial Post on: Friday, 10-Jun-05 14:10:30
Last modified on: Friday, 10-Jun-05 14:22:48