Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
BID:10392
Info
Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 10392 |
| Class: | Design Error |
| CVE: |
CVE-2004-048 CVE-2004-0487 |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This issue is credited to Yuu Arai of LAC (Little eArth Corporation, Ltd). |
| Vulnerable: |
Symantec Norton AntiVirus 2004 |
| Not Vulnerable: | |
Discussion
Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
Symantec Norton AntiVirus is prone to a remote code execution vulnerability. This issue presents itself in an ActiveX control used by the application and could allow an attacker to execute arbitrary executables, launch URI pop-up windows, and carry out denial of service attacks against the antivirus application.
Norton AntiVirus 2004 is prone to this vulnerability.
Symantec Norton AntiVirus is prone to a remote code execution vulnerability. This issue presents itself in an ActiveX control used by the application and could allow an attacker to execute arbitrary executables, launch URI pop-up windows, and carry out denial of service attacks against the antivirus application.
Norton AntiVirus 2004 is prone to this vulnerability.
Exploit / POC
Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
Solution:
A fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
Solution:
A fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
References
Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability
References:
References: