OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Symantec LiveState Agent for Windows vulnerabi

From: Damjan (damjanwidesec.com)
Date: Tue Dec 05 2006 - 14:09:40 CST


> >> we've found local privilege escalation in Symantec LiveState agent.
> >>
> >> PoC:
> >>
> >> 1. kill shstart.exe process
>
> MS> Wouldn't you have to be administrator to kill shstart.exe?
>
> LocalSystem account has more privilegies then administrator's one.

I don't think so. I think, SYSTEM account has less or same privileges than Administrator. Or?

Greetings