CVE-2011-3478
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 39%
from disclosure to weapon154 days
Published on NVDJan 25
1st PoC+154d
exploitation probability
39%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/38599/unverifiedexploitdbwww.exploit-db.com/exploits/19407unverifiedexploitdbwww.exploit-db.com/exploits/38599unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/show/osvdb/78532http://secunia.com/advisories/48092https://www.exploit-db.com/exploits/38599/http://www.securityfocus.com/bid/51592http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120124_00http://www.zerodayinitiative.com/advisories/ZDI-12-018/