Werk #16173: symantec_av: Don't run sav command if it isn't owned by root

Component Checks & agents
Title symantec_av: Don't run sav command if it isn't owned by root
Date Feb 28, 2024
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.4.0b1
Not yet released
Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)
2.3.0b1 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)
2.2.0p24 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)

Symantec Anti Virus plugin uses /opt/Symantec/symantec_antivirus/sav command to monitor a Symantec Anti Virus installation.

To prevent privilege escalation, the plugin (which is run by root user) must not run executables which can be changed by less privileged users.

In the default installation, sav command is owned by root and root is the only user with write permissions, which prevents privilege escalation attacks.

With this Werk, the plugin checks if sav command is owned by root and root is the only user with write permissions before running the command. If that's not the case the command won't be run. This prevents privilege escalation attacks if the permissions of the sav command have been changed.

We rate this with a CVSS of 0 (None) (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N). This CVSS is primarily meant to please automatic scanners.

CMK-15318

To the list of all Werks