Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
BID:24983
Info
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 24983 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2955 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2007 12:00AM |
| Updated: | Aug 09 2007 06:04PM |
| Credit: | Carsten Eiram of Secunia Research reported this issue to the vendor. |
| Vulnerable: |
Symantec Norton System Works 2006 Symantec Norton Internet Security 2006 0 Symantec Norton Internet Security 2005 Anti Spyware Edition 0 Symantec Norton AntiVirus 2006 |
| Not Vulnerable: | |
Discussion
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
Multiple Symantec Norton products are prone to a remote code-execution vulnerability. This issue occurs in ActiveX controls that are shared across multiple products.
Invoking the object from a malicious website or HTML email may trigger this condition. Successful exploits allow remote attackers to execute code and to compromise affected computers. Failed exploit attempts likely result in computer crashes.
The following products are vulnerable to this issue:
Norton Antivirus 2006
Norton Internet Security 2006
Norton Internet Security, Anti Spyware Edition 2005
Norton System Works 2006
Multiple Symantec Norton products are prone to a remote code-execution vulnerability. This issue occurs in ActiveX controls that are shared across multiple products.
Invoking the object from a malicious website or HTML email may trigger this condition. Successful exploits allow remote attackers to execute code and to compromise affected computers. Failed exploit attempts likely result in computer crashes.
The following products are vulnerable to this issue:
Norton Antivirus 2006
Norton Internet Security 2006
Norton Internet Security, Anti Spyware Edition 2005
Norton System Works 2006
Exploit / POC
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
Solution:
Symantec has released an advisory and fixes to address this issue. Users of affected packages should use the interactive LiveUpdate feature to obtain and apply fixes.
Please see the references for more information.
Solution:
Symantec has released an advisory and fixes to address this issue. Users of affected packages should use the interactive LiveUpdate feature to obtain and apply fixes.
Please see the references for more information.
References
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Norton AntiVirus Product Homepage (Symantec)
- Norton Internet Security Homepage (Symantec)
- SYM07-021: Symantec ActiveX Control Input Validation Error (Symantec)