LOW · 3.3

CVE-2012-6348

Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, o...

Vulnerability Description

Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbitrary files and consequently gain privileges via a symlink attack on the centrify.cmd.0 temporary file.

CVSS Score

3.3

LOW

AV:L/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CentrifyCentrify Deployment Manager2.1.0.283
CentrifyCentrify Suite<= 2012

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-6348?

CVE-2012-6348 is a vulnerability with a CVSS score of 3.3 (LOW). Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, o...

How severe is CVE-2012-6348?

CVE-2012-6348 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-6348?

Check the references section above for vendor advisories and patch information. Affected products include: Centrify Centrify Deployment Manager, Centrify Centrify Suite.