CVE-2012-0304: Symantec Liveupdate Administrator
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
Affected products
- Symantec Liveupdate Administrator: up to and including 2.3.0; version 1.5.3.21 only; version 1.5.4 only; version 1.5.7.19 only; version 2.1.0 only; version 2.1.2 only; …
Published 2012-06-22. Last modified 2026-06-16.