Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. <a href"http://cwe.mitre.org/data/definitions/426.html">CWE-426: Untrusted Search Path</a>
Publication date: Wed, 22 Apr 2015 15:59:00 +0000