lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
From: reedarvin at (Reed Arvin)
Subject: Privilege escalation flaw in the AClient Service for Windows (Version 5.6.181).

A privilege escalation flaw exists in the AClient Service for Windows
(Version 5.6.181) (

A privilege escalation technique can be used to gain SYSTEM level
access while interacting with the AClient Service for Windows tray

Vulnerable Versions:
Altiris Deployment Solution 5.6 SP1 (Hotfix E)

The vendor was notified of the issue. There was no technical response.
The vendor will not give support without a support contract.

1. Right click on the Altiris Client Service icon in the Taskbar and
choose View Log File
2. Notepad should open. Click File, click Open
3. In the Files of type: field choose All Files
4. Navagate to %WINDIR%\System32\
5. Right click on cmd.exe and choose Open
6. A new command shell with launch with SYSTEM privileges

Discovered by Reed Arvin reedarvin[at]gmail[dot]com

Powered by blists - more mailing lists