vendor:
PcAnywhere
by:
S2 Crew [Hungary]
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: PcAnywhere
Affected Version From: 12.5.2000
Affected Version To: 12.5.2000
Patch Exists: NO
Related CWE: CVE-2011-3478
CPE: symantec:pcanywhere
Platforms Tested: Windows XP SP2
2012
Symantec PcAnywhere login and password field buffer overflow
This exploit targets a buffer overflow vulnerability in the login and password fields of Symantec PcAnywhere. By sending a specially crafted payload, an attacker can overwrite adjacent memory and potentially execute arbitrary code.
Mitigation:
Update to a patched version of Symantec PcAnywhere or apply the vendor-provided patch for this vulnerability. Avoid using default or weak credentials.