ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability
ZDI discloses CVE-2024-13962, a CVSS 7.8 link-following local privilege escalation flaw in Norton Utilities Ultimate's NortonUtilitiesSvc service.
The Zero Day Initiative published ZDI-26-567, a local privilege escalation vulnerability in Norton Utilities Ultimate. An attacker must already be able to execute low-privileged code on the system before exploiting the symlink/link-following flaw in NortonUtilitiesSvc. The issue carries a CVSS score of 7.8 and is tracked as CVE-2024-13962.
- Local privilege escalation in Norton Utilities Ultimate via NortonUtilitiesSvc
- Requires prior low-privileged code execution to exploit
- CVSS 7.8, assigned CVE-2024-13962, disclosed via ZDI-26-567
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-13962 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack. NVD description · AI analysis pending | 7.8 | <1% | — | — |
This vulnerability allows local attackers to escalate privileges on affected installations of Norton Utilities Ultimate. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13962.
This source does not provide full text. Read it at zerodayinitiative.com.