Symantec AntiVirus Scan Evasion Vulnerability
BID:38219
Info
Symantec AntiVirus Scan Evasion Vulnerability
| Bugtraq ID: | 38219 |
| Class: | Design Error |
| CVE: |
CVE-2010-0106 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Mar 02 2010 11:22PM |
| Credit: | Jeffrey Walton and Dr. Brooke Stephens |
| Vulnerable: |
Symantec Client Security 3.1.4 MR4 MP1 - build 4010 Symantec Client Security 3.1.4 .4000 (MR4) Symantec Client Security 3.1 .401 Symantec Client Security 3.1 .400 Symantec Client Security 3.1 .396 Symantec Client Security 3.1 .394 Symantec Client Security 3.0.2 .2021 Symantec Client Security 3.0.2 .2020 Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0.1 .1009 (MR1-PP9) Symantec Client Security 3.0.1 .1003 (MR1-PP2) Symantec Client Security 3.1 MR9 Symantec Client Security 3.1 MR8 Symantec Client Security 3.1 MR7 Symantec Client Security 3.1 MR6 MP1 Symantec Client Security 3.1 MR6 Symantec Client Security 3.1 Symantec Client Security 3.0.1.1008 Symantec Client Security 3.0.1.1007 Symantec Client Security 3.0.1.1001 Symantec Client Security 3.0.1.1000 Symantec Client Security 3.0.0.359 Symantec AntiVirus for Macintosh 10.0 Symantec AntiVirus for Macintosh 10.2 Symantec AntiVirus for Macintosh 10.1 Symantec AntiVirus for Macintosh 10.0 Symantec AntiVirus Corporate Edition 10.2.1 .1000 (MR1) Symantec AntiVirus Corporate Edition 10.2 .313 (STM-PP1) Symantec AntiVirus Corporate Edition 10.2 .298 (STM 64-bit) Symantec AntiVirus Corporate Edition 10.2 .276 (STM 32-bit) Symantec AntiVirus Corporate Edition 10.1.7 .7000 (MR7) Symantec AntiVirus Corporate Edition 10.1.6 .6010 (MR6-MP1) Symantec AntiVirus Corporate Edition 10.1.5 .5010 (MR5-MP1) Symantec AntiVirus Corporate Edition 10.1.5 .5001 (MR5-PP1) Symantec AntiVirus Corporate Edition 10.1.5 .5000 (MR5) Symantec AntiVirus Corporate Edition 10.1.4 MR4 MP1 - build 4010 Symantec AntiVirus Corporate Edition 10.1.4 .4000 (MR4) Symantec AntiVirus Corporate Edition 10.1.4 Symantec AntiVirus Corporate Edition 10.1 .401 Symantec AntiVirus Corporate Edition 10.1 .400 Symantec AntiVirus Corporate Edition 10.1 .396 Symantec AntiVirus Corporate Edition 10.1 .394 Symantec AntiVirus Corporate Edition 10.0.2 .2021 Symantec AntiVirus Corporate Edition 10.0.2 .2020 Symantec AntiVirus Corporate Edition 10.0.2 .2011 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2002 Symantec AntiVirus Corporate Edition 10.0.2 .2001 Symantec AntiVirus Corporate Edition 10.0.2 .2000 Symantec AntiVirus Corporate Edition 10.0.1 .1009 (MR1-PP9) Symantec AntiVirus Corporate Edition 10.0.1 .1003 (MR1-PP2) Symantec AntiVirus Corporate Edition 10.0.1 .1001 (MR1-PP1) Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 10.2 MR3 Symantec AntiVirus Corporate Edition 10.2 MR2 Symantec AntiVirus Corporate Edition 10.2 MR1 Symantec AntiVirus Corporate Edition 10.2 Symantec AntiVirus Corporate Edition 10.1.6.6000 Symantec AntiVirus Corporate Edition 10.1.6.600 Symantec AntiVirus Corporate Edition 10.1.4.4010 Symantec AntiVirus Corporate Edition 10.1 MR8 Symantec AntiVirus Corporate Edition 10.1 MR7 Symantec AntiVirus Corporate Edition 10.1 MR6 MP1 Symantec AntiVirus Corporate Edition 10.1 MR6 Symantec AntiVirus Corporate Edition 10.1 Symantec AntiVirus Corporate Edition 10.0.2.2000 Symantec AntiVirus Corporate Edition 10.0.1.1008 Symantec AntiVirus Corporate Edition 10.0.1.1007 Symantec AntiVirus Corporate Edition 10.0.1.1000 Symantec AntiVirus Corporate Edition 10.0.0.359 |
| Not Vulnerable: | |
Discussion
Symantec AntiVirus Scan Evasion Vulnerability
Symantec AntiVirus is prone to a vulnerability that may allow an attacker to bypass on-demand scans.
Successful exploits will allow attackers to bypass on-demand virus scanning, possibly allowing malicious files to escape detection.
Update (March 1, 2010): Attackers require local access to exploit this issue. Symantec AntiVirus 11.x is not affected by this issue.
Update (March 2, 2010): Symantec Endpoint Protection is not affected by this issue.
The following products are affected:
Symantec AntiVirus 10.0.x
Symantec AntiVirus 10.1.x
Symantec AntiVirus 10.2.x
Symantec Client Security 3.0.x
Symantec Client Security 3.1.x
Symantec AntiVirus is prone to a vulnerability that may allow an attacker to bypass on-demand scans.
Successful exploits will allow attackers to bypass on-demand virus scanning, possibly allowing malicious files to escape detection.
Update (March 1, 2010): Attackers require local access to exploit this issue. Symantec AntiVirus 11.x is not affected by this issue.
Update (March 2, 2010): Symantec Endpoint Protection is not affected by this issue.
The following products are affected:
Symantec AntiVirus 10.0.x
Symantec AntiVirus 10.1.x
Symantec AntiVirus 10.2.x
Symantec Client Security 3.0.x
Symantec Client Security 3.1.x
Exploit / POC
Symantec AntiVirus Scan Evasion Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec AntiVirus Scan Evasion Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
Symantec AntiVirus Scan Evasion Vulnerability
References:
References: