Symantec pcAnywhere awhost32 Remote Code Execution
Critical Nessus Plugin ID 58119
SynopsisThe remote service is affected by a remote code execution vulnerability.
DescriptionA flaw exists within the awhost32 component of the remote pcAnywhere that is used when handling incoming connections from remote hosts. When handling an authentication request, the process copies the user supplied username unsafely to a fixed-length buffer of size 0x108. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the SYSTEM account.
SolutionApply Symantec's patch.