ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability

lowAdvisoryimportance 15CVE-2024-13962
AI summary · glm-5.3-flash

ZDI discloses CVE-2024-13962, a CVSS 7.8 link-following local privilege escalation flaw in Norton Utilities Ultimate's NortonUtilitiesSvc service.

The Zero Day Initiative published ZDI-26-567, a local privilege escalation vulnerability in Norton Utilities Ultimate. An attacker must already be able to execute low-privileged code on the system before exploiting the symlink/link-following flaw in NortonUtilitiesSvc. The issue carries a CVSS score of 7.8 and is tracked as CVE-2024-13962.

  • Local privilege escalation in Norton Utilities Ultimate via NortonUtilitiesSvc
  • Requires prior low-privileged code execution to exploit
  • CVSS 7.8, assigned CVE-2024-13962, disclosed via ZDI-26-567

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13962
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc.

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

NVD description · AI analysis pending
7.8<1%
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Norton Utilities Ultimate. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13962.

This source does not provide full text. Read it at zerodayinitiative.com.