<<< Date Index >>>     <<< Thread Index >>>

Re: Symantec LiveState Agent for Windows vulnerabi



>>>>> "D" == Damjan  <damjan@xxxxxxxxxxx> writes:

 >> >> we've found local privilege escalation in Symantec LiveState agent.
 >> >> 
 >> >> PoC:
 >> >> 
 >> >> 1. kill shstart.exe process
 >> 
 MS> Wouldn't you have to be administrator to kill shstart.exe?
 >> 
 >> LocalSystem account has more privilegies then administrator's one.


 D> I don't think so. I think, SYSTEM account has less or same
 D> privileges than Administrator. Or? 

SeTCBPrivilege SeCreateTokenPrivilege

-- 
Yours sincerely, Eugeny.
Doctor Web, Ltd. http://www.drweb.com