Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability.
Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file.
A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server.
Vendor Status:
Symantec as issued an update for this vulnerablity