Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
BID:9915
Info
Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
| Bugtraq ID: | 9915 |
| Class: | Design Error |
| CVE: |
CVE-2004-0364 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery is credited to Mark Litchfield. |
| Vulnerable: |
Symantec Norton Personal Firewall 2004 Symantec Norton Personal Firewall 2003 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Client Security 1.0 Symantec Client Firewall 5.1.1 Symantec Client Firewall 5.0 1 |
| Not Vulnerable: | |
Discussion
Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
Symantec firewall products such as Norton Internet Security, Norton Personal Firewall, Client Firewall and Client Security are prone to a vulnerability that may potentially allow for remote command execution.
This vulnerability is exposed via the WrapNISUM Class ActiveX component. This component may potentially be invoked to launch a resource via a UNC path from malicious web page or HTML e-mail. This resource would likely be a malicious attacker-supplied executable.
Symantec firewall products such as Norton Internet Security, Norton Personal Firewall, Client Firewall and Client Security are prone to a vulnerability that may potentially allow for remote command execution.
This vulnerability is exposed via the WrapNISUM Class ActiveX component. This component may potentially be invoked to launch a resource via a UNC path from malicious web page or HTML e-mail. This resource would likely be a malicious attacker-supplied executable.
Exploit / POC
Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
Solution:
Symantec has released advisory SYM04-005 relating to this issue. Please see the reference section for more information.
Fixes for all affected products except Client Firewall and Client Security may be applied via LiveUpdate. Client Firewall and Client Security fixes may be obtained by customers through proper support channels.
Solution:
Symantec has released advisory SYM04-005 relating to this issue. Please see the reference section for more information.
Fixes for all affected products except Client Firewall and Client Security may be applied via LiveUpdate. Client Firewall and Client Security fixes may be obtained by customers through proper support channels.
References
Symantec Firewall Products WrapNISUM Class Remote Command Execution Vulnerability
References:
References:
- SYM04-005 Symantec Norton Internet Security and Norton AntiSpam Remote Access... (Symantec)
- Norton Internet Security Remote Command Execution (#NISR19042004b) ("NGSSoftware Insight Security Research"
)