A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
| Vendor | Product | Versions |
|---|---|---|
| broadcom | symantec management suite | before SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5 |
Updated severity from NONE to CRITICAL based on 'very critical' rating; assigned CVSS estimate of 9.0 and CWE-269 (Improper Access Control / Privilege Management)
Initial creation