| CVE-2025-13032 - Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privileges via pool overflow. | |
| Severity/CVSSv4.0 | 9.9 (CRITICAL) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2025-13032 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privileges via pool overflow.
|
| Additional Recommendations, if any: | Upgrade to a version after >= 25.3 |
| Acknowledgements | SAFA Team |
| CVE-2025-10905 - Collision in minifilter driver of Avast Free Antivirus results in disabling of real-time protection | |
| Severity/CVSSv4.0 | 4.4 (MEDIUM) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2025-10905 |
| Impact | CAPEC-578 Disable Security Software |
| Description |
Collision in MiniFilter driver in Avast Software Avast Free Antivirus before 25.9 on Windows allows a local attacker with administrative privileges to disable real-time protection and self-defense mechanisms.
|
| Additional Recommendations, if any: | Upgrade to Avast 25.9 or newer |
| Acknowledgements | Dongchan Seo |
| CVE-2025-3025 - CCleaner Link Following Local Privilege Escalation Vulnerability | |
| Severity/CVSSv4.0 | 7.3(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13961 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCLeaner v. 6.33.11465. This issue affects CCleaner: before < 6.36.11508.
|
| Additional Recommendations, if any: | Upgrade to v. 6.36.11508, or newer, released 28/MAY/2025 |
| Acknowledgements | Dong-uk Kim (@justlikebono); Trend Micro, the Zero Day Initiative (ZDI) ZDI-CAN-26474 |
| CVE-2024-13962 - Link Following Local Privilege Escalation Vulnerability in Avast Cleanup Premium Version 24.2.16593.17810 | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13962 |
| Impact | CAPEC-233 Privilege Escalation; CAPEC-549 Local Execution of Code |
| Description |
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
|
| Additional Recommendations, if any: | Upgrade to Avast Cleanup Premium 24.3.17165.19178 or newer |
| Acknowledgements | Vladislav Berghici of Trend Micro; Zero Day Initiative |
| CVE-2024-13961 - Avast Cleanup Premium TuneupSvc Link Following Local Privilege Escalation Vulnerability | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13961 |
| Impact | CAPEC-233 Privilege Escalation; CAPEC-549 Local Execution of Code |
| Description |
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
|
| Additional Recommendations, if any: | Update to Avast Cleanup Premium 24.3.17165.19178 or newer |
| Acknowledgements | Vladislav Berghici of Trend Micro Research; Zero Day Initiative |
| CVE-2024-13960 - Link Following Local Privilege Escalation Vulnerability in AVG TuneUp Version 23.4 | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13960 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
|
| Additional Recommendations, if any: | Update to v24.1 31.7.2024 or newer. |
| Acknowledgements | Zero Day Initiative |
| CVE-2024-13959 - Link Following Local Privilege Escalation Vulnerability in AVG TuneUp 24.2.16593.9844 | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13959 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging the service to delete a directory
|
| Additional Recommendations, if any: | An upgrade was released on 11.12.2024 in version AVG TuneUp 24.3.17165.10564, upgrade to this or later version. |
| Acknowledgements | Vladislav Berghici of Trend Micro; Zero Day Initiative |
| CVE-2024-13944 - Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate (Also affects Avast CleanUp and AVG TuneUp) | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13944 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
|
| Additional Recommendations, if any: |
Upgrade to the below versions, or newer, released 19/Dec/2024
|
| Acknowledgements |
Vladislav Berghici of Trend Micro Research; Zero Day Initiative
|
| CVE-2024-13759 - Local Privilege Escalation in Avira Prime 1.1.96.2 on Windows 10 x64 | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-13759 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attackers to gain system-level privileges via arbitrary file deletion
|
| Additional Recommendations, if any: | Upgrade to the latest version of Avira Prime |
| Acknowledgements | Anonymous working with Trend Micro Zero Day Initiative |
| CVE-2024-9524 - Privilege Escalation Vulnerability in Avira Prime Version 1.1.96.2 | |
| Severity/CVSSv4.0 | 7.8(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-9524 |
| Impact | CAPEC-233 Privilege Escalation; CAPEC-549 Local Execution of Code |
| Description |
Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
|
| Additional Recommendations, if any: | Fix released 03/Dec/2024, upgrade to the latest version. |
| Acknowledgements | Anonymous working with Trend Micro Zero Day Initiative |
| CVE-2024-9484 - N/A | |
| Severity/CVSSv4.0 | 5.1(MEDIUM) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-9484 |
| Impact | N/A |
| Description |
An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.
|
| Additional Recommendations, if any: | Upgrade to the latest version of virus definitions. |
| Acknowledgements | Mike Zhang, an independent security researcher |
| CVE-2024-9483 - Uninitialized variable in digital signiture verification may crash the application | |
| Severity/CVSSv4.0 | 5.1 (MEDIUM) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-9483 |
| Impact | N/A |
| Description |
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
|
| Additional Recommendations, if any: | Upgrade to the latest version of virus definitions. |
| Acknowledgements | Mike Zhang, an independent security researcher |
| CVE-2024-9482 - Out of Bounds write on scan of malformed Mach-O file may crash the application | |
| Severity/CVSSv4.0 | 5.1(MEDIUM) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-9482 |
| Impact | N/A |
| Description |
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.
|
| Additional Recommendations, if any: | Upgrade to the latest version of virus definintions. |
| Acknowledgements | Mike Zhang, an independent security researcher |
| CVE-2024-9481 - Out of Bounds write on scan of malformed eml file may crash the application | |
| Severity/CVSSv4.0 | 5.1(MEDIUM) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-9481 |
| Impact | N/A |
| Description |
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.
|
| Additional Recommendations, if any: | Upgrade to the latest version of virus definitions. |
| Acknowledgements | Mike Zhang, an independent security researcher |
| CVE-2024-5803 - Local privelage escalation via COM hijacking | |
| Severity/CVSSv4.0 | 7.5(HIGH) |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-5803 |
| Impact | CAPEC-233 Privilege Escalation |
| Description |
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
|
| Additional Recommendations, if any: | N/A |
| Acknowledgements | Cirosec GmbH |
| CVE-2024-5102 | |
| Severity/CVSSv4.0 | Severity: HighScore:7.3 Vector: CVSS:4.0/AV:L/AC:H/AT/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| References | https://nvd.nist.gov/vuln/detail/CVE-2024-5102 |
| Impact | Escalation of privelage |
| Description | A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the system files and make Windows callback to a specially-crafted file which could be used to launch a privileged shell instance. This issue affects Avast Antivirus prior to 24.2. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software is always updated to the latest version available. Acknowledgements Naor Hodorov |
| NLOKSA1516 | Ttime-of-check to time-of-use (TOCTOU) can lead to local privilege escalation." |
| Advisory Status | CLOSED |
| Summary | The aswSnx.sys driver contains a time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system. |
| Affected Products | Avast/AVG Antivirus 23.8 |
| Issues | Mitigation The issue was fixed with Avast/AVG Antivirus version 23.9. AcknowledgementsWei Sheng Teo of Ensign InfoSecurity |
| CVE-2023-5760 | |
| Severity/CVSSv3 | Severity: Low Score:3.9 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N |
| References | https://nvd.nist.gov/vuln/detail/CVE-2023-5760 |
| Impact | Escalation of privelage |
| Description | A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software is always updated to the latest version available. |
| NLOKSA1515 | Integer Overflow Local Privilege Escalation Vulnerability |
| Advisory Status | CLOSED |
| Summary | A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation |
| Affected Products | Avira Antivirus for Windows Endpointprotection.exe version before 1.0.2303.633 |
| Issues | Mitigation Issue was fixed with Endpointprotection.exe version 1.0.2303.633 released on 03-04-2023. All users will receive the update automatically, no user action is required AcknowledgementsRac working with Trend Micro Zero Day Initiative |
| CVE-2023-1900 | |
| Severity/CVSSv3 | Severity: High Score: 7.8 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| References | https://nvd.nist.gov/vuln/detail/CVE-2023-1900 |
| Impact | Integer Overflow Local Privilege Escalation Vulnerability |
| Description | A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation. Issue was fixed with Endpointprotection.exe version 1.0.2303.633 |
| Additional Recommendations, if any: | We encourage customers to ensure their security software is always updated to the latest version available. |
| NLOKSA1511 | Avira Security for Windows - Denial of Service |
| Advisory Status | CLOSED |
| Summary | Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service |
| Affected Products | Avira Security for Windows up to version 1.1.77 |
| Issues | Mitigation Upgrade Avira Security for Windows to version 1.1.78. This version was released on 22 November 2022 to all customers. All users received the update automatically and do not need to take any action. AcknowledgementsYangHao / https://github.com/yanghaoi |
| CVE-2022-4429 | |
| Severity/CVSSv3 | Severity: Medium Score: 5.3 Vector: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H&version=3.1 |
| References | https://nvd.nist.gov/vuln/detail/CVE-2022-4429 |
| Impact | Denial of Service |
| Description | Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service The issue was fixed with Avira Security version 1.1.78 |
| Additional Recommendations, if any: | We encourage customers to ensure their security software are always updated to the latest version available. |
| NLOKSA1510 | Norton, Avira, Avast and AVG Antivirus for Windows Privilege Escalation |
| Advisory Status | CLOSED |
| Summary | Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. |
| Affected Products | Norton Antivirus Windows Eraser Engine Prior to 119.1.5.1 Avira Security for Windows Prior to version 1.1.78 Avast Antivirus Windows Prior to versions 22.10 AVG Antivirus Windows Prior to versions 22.10 |
| Issues | Mitigation Norton Antivirus: Run LiveUpdate, Updates to ERASER Engine 119.1.5.1, dated October 5th, 2022, or greater Bahaa Naamneh, Crosspoint Labs |
| CVE-2022-4294 | |
| Severity/CVSSv3 | Severity: High Score: 7.1 Vector: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H&version=3.1 |
| References | https://nvd.nist.gov/vuln/detail/CVE-2022-4294 |
| Impact | Privilege Escalation |
| Description | Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. The issue was fixed with Avast and AVG Antivirus version 22.10, Norton Antivirus ERASER Engine 119.1.5.1 and Avira Security version 1.1.78 |
| Additional Recommendations, if any: | We encourage customers to ensure their security software are always updated to the latest version available. |
| NLOKSA1509 | Aswjsflt.dll in Avast Antivirus windows caused a crash of the Mozilla Firefox browser due to heap corruption |
| Advisory Status | CLOSED |
| Summary | From October 6, 2022 to October 8, 2022, Avast Antivirus windows (Script Shield component versions 18.0.1473.0 and older) caused a crash of the Mozilla Firefox browser due to heap corruption occurring when the Avast DLL library was loaded. Avast and Mozilla have since been working together to mitigate the issue. Avast issued an update to its software on October 8, 2022, to version 18.0.1478. No user action is required as users received this update automatically. |
| Affected Products | Script Shield component versions 18.0.1473.0 and older |
| Issues | Mitigation Avast issued an update to its Script Shield software on October 8, 2022, to version 18.0.1478. No user action is required as users received this update automatically. AcknowledgementsMozilla |
| CVE-2022-4291 | |
| Severity/CVSSv3 | Severity: High Score: 7.7 Vector: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L/RL:O/RC:R |
| References | https://crash-stats.mozilla.org/report/index/926cf73c-7bdd-4774-a094-1e9f60221008 https://nvd.nist.gov/vuln/detail/CVE-2022-4291 |
| Impact | Heap Corruption |
| Description | The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software – as well as their tech devices – are always updated to the latest version available. |
| NLOKSA1508 | Avast and AVG Antivirus for Windows vulnerable to Privilege Escalation |
| Advisory Status | CLOSED |
| Summary | Avast has released an update to address an issue that was discovered in the malware removal functionality of Avast and AVG Antivirus. |
| Affected Products | Avast Antivirus - up to version 22.9, starting with version 20.5 AVG Antivirus - up to version 22.9, starting with version 20.5 |
| Issues | Mitigation Upgrade Avast and AVG Antivirus for Windows to version 22.10 released on 20 October 2022. By default, users of the affected versions should receive the update automatically, they only need to restart Windows to apply the update once Avast / AVG asks them to do so. AcknowledgementsOr Yair / https://www.safebreach.com |
| CVE-2022-4173 | |
| Severity/CVSSv3 | Severity: High Score: 7.3 Vector: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| References | https://nvd.nist.gov/vuln/detail/CVE-2022-4173 |
| Impact | Privilege Escalation |
| Description | A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software are always updated to the latest version available. |
| NLOKSA1507 | Software Updater of Avira Security for Windows vulnerable to Privilege Escalation |
| Advisory Status | CLOSED |
| Summary | NortonLifeLock has released an update to address an issue that was discovered in the software updater functionality of Avira Security. |
| Affected Products | "Avira Security" – for Windows; up to version 1.1.71.30554 |
| Issues | Mitigation Upgrade Avira Security for Windows to version 1.1.72.30556. This version was released on 15. August 2022 to all customers. All users received the update automatically and do not need to take any action. AcknowledgementsFilip Dragovic |
| CVE-2022-3368 | |
| Severity/CVSSv3 | High Score: 7.3 Vector: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| References | Filip Dragovic |
| Impact | Privilege Escalation |
| Description | A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software – as well as their tech devices – are always updated to the latest version available. |
| NLOKSA1506 | Avira Password Manager-Browser Extensions vulnerable to Sensitive Data Leakage via Phishing |
| Advisory Status | CLOSED |
| Summary | NortonLifeLock has released an update to address an issue that was discovered in Avira Password Manager Browser Extension |
| Affected Products | Only the following software is affected:
|
| Issues | Mitigation Upgrade extensions to following versions:
Users who have not disabled auto-updates receive the updated versions automatically and do not need to take any action AcknowledgementsStiftung Warentest |
| CVE-2022-28795 | |
| Severity/CVSSv3 | Critical Score: 9.6 Vector: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| References | https://nvd.nist.gov/vuln/detail/CVE-2022-28795 |
| Impact | Sensitive Data Leakage |
| Description | A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari. |
| Additional Recommendations, if any: | We encourage customers to ensure their security software - as well as their tech devices - are always updated to the latest version available. In addition, we encourage users to use two-factor (2FA) authentication as an additional layer of security. |
SYMSA1003 |
Norton AntiVirus 2002 Beta Security Issues |
Advisory Status |
CLOSED |
| Summary |
SecuriTeam's advisory references two issues. The first issue is a weak password scheme used with NAV's Quarantine that could be brute force decrypted to bypass the password protection or bypassed completely by modifying the appropriate .dat file. The second issue is the Norton AntiVirus AutoProtect service can be deactivated. Security AlertDTD: 24 July, 2001
--> |
| Affected Products |
Affected:Norton AntiVirus 2002 Beta for Windows
|
| Issues |
Details:Norton AntiVirus 2002 beta Quarantine Password encryption - When Norton AntiVirus finds a file it can't repair; it safely isolates the file in a quarantine area. Quarantine is a repository for files that have been infected by viruses. Inside Quarantine, viruses are unable to spread into other areas of your computer. Preventing viruses from spreading safeguards your computer from further damage.
Mitigation Resolution:The primary purpose of Norton AntiVirus 2002 beta Quarantine password is to prevent inadvertent or intentional unauthorized changes to selected options, it is not to provide strong application security. The available options on the quarantine UI do not change or modify any form of Norton AntiVirus protection nor do they hold any important data. If the password option is selected, the user/administrator should protect their password as an enhancement to physical and personal security policies and features. Norton AntiVirus 2002 beta AutoProtect service deactivated - AutoProtect is the name of the Norton AntiVirus real time scanner. Real time scanners are a typical feature found in a variety of antivirus software packages to automatically scan files being downloaded, copied, or executed on a workstation. With AutoProtect enabled under Norton AntiVirus, this service loads each time the machine is booted. Under a normal system configuration this service continues to run and scan files until the machine is powered off. SecuriTeam's advisory reports the startup method can be modified by changing the values in the registry controlling the behavior of the AutoProtect service. They further provide a JavaScript program that, if allowed to execute on the system, can change the Norton AntiVirus AutoProtect service from enabled to disabled. In the disabled configuration, the AutoProtect Service will not start up automatically the next time the targeted system is rebooted or restarted. Resolution:Norton AntiVirus 2002 beta real time and on demand scanners cannot be disabled through changes to the registry. Norton AntiVirus customers are completely safe. If a software tool were created to access the registry and modify any keys that would affect Norton AntiVirus components, a definition would be created to detect and stop that tool just as it would stop a virus. Further, Script Blocking prevents the script developed to automate the disable of AutoProtect from executing on the targeted system. Acknowledgements Symantec appreciates the support of Daniel Wischnewski and Beyond Security's SecuriTeam in identifying areas of concern so we can quickly address them References Reference:Beyond-Security's SecuriTeam.com Security Advisory, Norton AntiVirus 2002 Security Flaws, dtd: 17/7/2001, http://www.securiteam.com/windowsntfocus/5GP0C2A4UO.html as reported by Daniel Wischnewski. Additional DataLegacy ID: SYM01-003 Owner: James Terrill Created: 24-JUL-01 12.00.00.000000000 AM Modified: 24-JUL-01 12.00.00.000000000 AM Classification: Norton |
SYMSA1005 |
Firewall log file permissions and file sharing parameters allow unauthorized log file access and mod |
Advisory Status |
CLOSED |
| Summary |
Symantec Corporation has been made aware of and is preparing an update to current Norton Internet Security, Norton Personal Firewall and Symantec Desktop Firewall products that corrects a potential exposure of the firewall logs to unauthorized modification. There is a potential issue with the file sharing parameters and default installation that could result in these logs file being modified or altered in a way that could affect the integrity of the logs and potentially be used in an attempt to hide unauthorized activity on the system. The exposure of the log files to potential modification does not in anyway affect the security of the product. File modification merely provides a potential way for an intruder to attempt to disguise their illegal activities. Reference:Nomad Mobile Research Centre (NMRC) Advisory, Subj: OpenFile Win32 API Log Overwriting/Rewriting Risk Impact:Low. --> |
| Affected Products |
Affected:Symantec Norton Internet Security 200x
|
| Issues |
Details:Symantec was notified by the NMRC of file sharing parameters issues in the way our desktop firewall applications open log files. This could possibly permit an unauthorized user on the system to potentially modify or delete the firewall logs in certain Symantec personal and Internet Security firewall products. The firewall log files are opened with FILE_SHARE_READ and FILE_SHARE_WRITE share access parameters. The issue here is that another application using the appropriate Win32 API call could potentially be used to re-open the firewall log files and overwrite the firewall log entries, even though the firewall application is running. Although the application's dialog tabs will still show the proper alert entries while the application is running, once the firewall service is stopped and restarted, the log entries reflect what was overwritten. Mitigation Symantec Response:Symantec's Desktop Firewall, Norton Internet Security System and Norton Personal Firewall provide intrusion protection, firewall rules, and application control to protect individual PCs and small-networked systems from online threats. The sensitive information logged to the firewall log files is an important part of properly maintaining the security of the system and providing information on inbound and outbound system activity. Symantec is constantly working to upgrade the security of our products and is currently testing an update to further secure the firewall logs from any unauthorized access and modifications. This security update will be available via LiveUpdate.
Acknowledgements Symantec takes the security of their products very seriously and appreciates the coordination of NMRC in identifying and providing technical details of potential areas of concern so we can quickly address the issue References Additional DataLegacy ID: SYM02-001 Owner: James Terrill Created: 22-JAN-02 12.00.00.000000000 AM Modified: 22-JAN-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1009 |
Symantec Norton AntiVirus Email Protection Bypass |
Advisory Status |
CLOSED |
| Summary |
Edvice Security Services Ltd. notified Symantec that Symantec Norton AntiVirus 2002 incoming email scanning protection could be bypassed by the following means:
ReferenceEdvice Security Services Ltd. Risk ImpactLow --> |
| Affected Products |
Symantec Norton AntiVirus 2002
|
| Issues |
DetailsEdvice Security Services Ltd. tested Symantec Norton AntiVirus 2002 and reported the following behaviors:
Mitigation Symantec ResponseSymantec feels that there are some basic misunderstandings concerning the impact of Edvice Security's findings. Symantec Norton AntiVirus products provide multiple-layered scanning to protect in these cases. Symantec customers are not in danger of being infected through any of these issues.
Acknowledgements Symantec takes the security and proper functionality of its products very seriously. Symantec appreciates the coordination of Mickey Boodaei and Edvice Security Services Ltd. in identifying and providing technical details of potential areas of concern so it can quickly address the issue. References Additional DataLegacy ID: SYM02-005 Owner: James Terrill Created: 07-MAR-02 12.00.00.000000000 AM Modified: 07-MAR-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1010 |
Symantec Norton AntiVirus 2002 Incoming Email Scan Bypass |
Advisory Status |
CLOSED |
| Summary |
The SECURITY.NNOV security group recently disclosed a potential way to bypass the incoming mail scan capabilities of Symantec Norton AntiVirus 2002 by using a non-RFC compliant format in the MIME header. ReferenceSECURITY.NNOV.RU Risk ImpactLow --> |
| Affected Products |
Affected ComponentsSymantec Norton AntiVirus 2002
|
| Issues |
DetailsSECURITY.NNOV tested Symantec Norton AntiVirus 2002 and reported that they could bypass the incoming mail scan capability by using a non-RFC compliant case in the incoming MIME header. According to SECURITY.NNOV, most mail user agents (MUA), the mail handler software that interfaces with the user, ignore the case of Content-Type and Content-Disposition headers while some content filtering software behaves in different ways to the non-RFC compliant headers. By mixing the case of the Content-Type and Content-Disposition headers as in the following example: CONTENT-type: text/plain; Mitigation Symantec ResponseSymantec researched this issue and feels that there are some basic misunderstandings concerning the impact of the SECURITY.NNOV findings.
Acknowledgements Symantec takes the security and proper functionality of its products very seriously. Symantec appreciates the identification of potential areas of concern so it can quickly address the issue. References Additional DataLegacy ID: SYM02-006 Owner: James Terrill Created: 03-APR-02 12.00.00.000000000 AM Modified: 03-APR-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1012 |
Symantec Norton Personal Firewall 2002 SYN/FIN scan issue |
Advisory Status |
CLOSED |
| Summary |
Symantec is aware of two issues with the Symantec Norton Personal Firewall 2002. A Microsoft Windows 2000 system is exposed during a SYN/FIN scan with Symantec Norton Personal Firewall 2002 installed. Additionally, a Jolt2 IP fragmentation attack will succeed against a non-patched Microsoft Windows 2000 computer running Symantec Norton Personal Firewall 2002. --> |
| Affected Products |
Components AffectedNorton Personal Firewall 2002
|
| Issues |
DescriptionOn 16 April, 2002, Symantec became aware of a SYN/FIN scan issue reported on SecurityFocus. By using a SYN/FIN scan, an attacker would be able to port scan a Microsoft Windows 2000 computer so that the computer responds even if Symantec Norton Personal Firewall 2002 is installed. A second reported issue states that a plain install of a Microsoft Windows 2000 system with Symantec Norton Personal Firewall 2002 installed is susceptible to a packet fragmentation denial of service (DoS) attack known as Jolt2. Mitigation Symantec ResponseSymantec has evaluated both issues. Although a Microsoft Windows 2000 computer can be detected through the SYN/FIN scan, Symantec Norton Personal Firewall 2002 continues to protect the computer from an actual intrusion by blocking connections to the computer. Acknowledgements References Additional DataLegacy ID: SYM02-008 Owner: James Terrill Created: 16-MAY-02 12.00.00.000000000 AM Modified: 16-MAY-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1015 |
Symantec Personal and Desktop Firewall Denial of Service Buffer Overflow |
Advisory Status |
CLOSED |
| Summary |
@stake notified Symantec of a denial of service problem with outgoing http request through the http filter component on the Symantec Norton Internet Security 2001 personal firewall. Certain malformed requests resulted in a general protection fault (GPF) on the system. --> |
| Affected Products |
Components AffectedSymantec Norton Internet Security 2001
|
| Issues |
DescriptionThe security professionals with @stake discovered a buffer overflow condition in the handling of outgoing http requests by the http filter on the Symantec Norton Internet Security 2001. During Symantec's testing this issue was found to impact the Symantec Norton Personal Firewall 2001 as well. The buffer overflow condition overwrites the first three bytes of the EDI register causing a kernel exception, resulting in a GPF on the targeted system and requiring a reboot. This exception occurs whether the firewall rules permit outgoing http connections or not. The Common Vulnerabilities and Exposures (CVE) initiative has assigned the name CAN-2002-0663 to this issue.
Mitigation Symantec ResponseSymantec engineers verified the buffer overflow condition exists in Symantec's Norton Internet Security 2001, Symantec's Norton Personal Firewall 2001 as well as Symantec's Desktop Firewall 2.0 and 2.01. They have further determined that the GPF does not occur in the latest release of Symantec's Norton Personal Firewall 2002, Norton Internet Security 2002, Norton Internet Security 2002 Professional Edition nor the Symantec Client Security, Symantec's integrated antivirus, intrusion detection and firewall replacement for Symantec Desktop Firewall. Acknowledgements Symantec takes the security and proper functionality of our products very seriously. Symantec appreciates the coordination of Ollie Whitehouse and @stake, Inc. in identifying and providing technical details of areas of concern as well as working closely with Symantec so we could properly address the issue. Anyone with information on security issues with Symantec products should contact symsecurity@symantec.com. References Additional DataLegacy ID: SYM02-011 Owner: James Terrill Created: 15-JUL-02 12.00.00.000000000 AM Modified: 15-JUL-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1020 |
Symantec Norton AntiVirus Corporate Edition 7.x Help File Elevation of Privilege |
Advisory Status |
CLOSED |
| Summary |
The Symantec Norton AntiVirus Corporate Edition client help function uses winhlp32, the Windows Help interface to provide help support to the client user. There is a vulnerability in the interface process that allow winhlp32 to assume privileges based on Norton AntiVirus Corporate Edition privileges rather those normally assigned to the winhlp32 interface. Since Norton AntiVirus Corporate Edition runs with SYSTEM privileges, the client user can manipulate the help function to access files on the local system with administrative privileges. --> |
| Affected Products |
Components AffectedSymantec Norton AntiVirus Corporate Edition prior to 7.5.1 build 62
|
| Issues |
DetailsSymantec became aware of an issue with the functionality of the Symantec Norton AntiVirus Corporate Edition GUI help interface that allows a client user to gain privileged access to files or functionality on the local system. Mitigation Symantec ResponseSymantec has verified that this vulnerability does exist in client applications of earlier versions of Symantec Norton AntiVirus Corporate Edition. This vulnerability has been eliminated in current versions of Symantec Norton AntiVirus Corporate Edition, version 7.5.1 Build 62 and later as well as version 7.6.1 Build 35a and later that are available for download.
Symantec strongly recommends all users of Symantec Norton AntiVirus Corporate Edition upgrade to the latest version release to prevent potential misuse of this weakness. Please see immediately below for instructions on upgrading: Platinum customersNew build downloads and product information are available on the Platinum Web site. Acknowledgements Symantec takes the security and proper functionality of its products very seriously. Symantec appreciates the efforts of Harry Johnson, Technical Support group, Waikato University, New Zealand in identifying and providing technical details of this issue. Symantec further appreciates the efforts of ERRor of Domain HELL Team for identification of this issue as well References Additional DataLegacy ID: SYM02-016 Owner: James Terrill Created: 15-OCT-02 12.00.00.000000000 AM Modified: 15-OCT-02 12.00.00.000000000 AM Classification: Norton |
SYMSA1022 |
Symantec Norton Internet Security ICMP Packet Flood Denial Of Service Vulnerability |
Advisory Status |
CLOSED |
| Summary |
Symantec is aware of an issue with the Symantec Norton Personal Firewall 2003. A Microsoft Windows 2000 or Windows XP system with Symantec Norton Personal Firewall 2003 installed can experience a crash when sending an excessively large echo request. --> |
| Affected Products |
Components AffectedNorton Personal Firewall 2003
|
| Issues |
DescriptionOn 13 January 2003, Symantec became aware of an issue originally reported on BugTraq. By sending an excessively large echo request, a crash can occur on a Windows 2000 or Windows XP system with Symantec Norton Personal Firewall 2003 installed Mitigation Symantec ResponseSymantec engineers have evaluated and verified that this issue exists for Symantec's Norton Personal Firewall 2003, Symantec's Norton Internet Security 2003 as well as Symantec's Norton Internet Security 2003 Professional Edition. Sending this excessively large echo request results in the overflow of an internal buffer and causes a crash of the system. This issue does not occur on systems running Windows 9x, Windows ME or Windows NT. Acknowledgements References Additional DataLegacy ID: SYM03-001 Owner: James Terrill Created: 17-JAN-03 12.00.00.000000000 AM Modified: 17-JAN-03 12.00.00.000000000 AM Classification: Norton |
SYMSA1023 |
Symantec Norton AntiVirus 2002 Buffer Overflow Vulnerability |
Advisory Status |
CLOSED |
| Summary |
Symantec is aware of an issue with Symantec Norton AntiViurs 2002 where a compressed zip file attachment that possess an overly long filename is scanned. This may lead to the execution of arbitrary code in the security context of the user currently logged onto the target system. An update for Symantec Norton AntiVirus 2002 to address this issue is now available via LiveUpdate. Localized versions of the patch are being worked on. --> |
| Affected Products |
Components AffectedNorton AntiVirus 2002
|
| Issues |
DescriptionOn December 26, 2002, Symantec became aware of an issue originally reported by the Security Net Services (SNS) security research group. By receiving a compressed zip file attachment with an excessively long file name, a buffer overflow can lead to arbitrary code in the security context of the user currently logged onto the target system. Mitigation Symantec ResponseSymantec engineers have evaluated and verified that this issue exists for Symantec's Norton AntiVirus 2002. Newer versions such as of Norton AntiVirus 2003 are not affected by this issue. Acknowledgements Symantec appreciates the support of Little eArth Corporation Co., Ltd (LAC), Japan. For information about their SecureNet Service advisories, visit their Web site References Additional DataLegacy ID: SYM03-002 Owner: James Terrill Created: 28-FEB-03 12.00.00.000000000 AM Modified: 28-FEB-03 12.00.00.000000000 AM Classification: Norton |
SYMSA1026 |
Symantec Norton AntiVirus Corporate Edition - Issue with Windows XP and floppy disk scan |
Advisory Status |
CLOSED |
| Summary |
Symantec's Norton AntiVirus Corporate Edition prevented the scanning of viruses on floppy disks when running Windows XP. --> |
| Affected Products |
Components AffectedNAV CE 7.60 build 926 with symevent 10.3.2.7
|
| Issues |
DescriptionThis issue was posted to Bugtraq on June 24, 2003 by Pal Juvancz of the Department of Public Works in Queensland, Australia. Mitigation Symantec ResponseThe issue was identified, reproduced and corrected with NAV CE 7.61 build 37b, with symevent 10.3.2.10. All subsequent builds work as designed. The customer verified that the problem was fixed and was upgraded to the latest release (8.01). Acknowledgements References Additional DataLegacy ID: SYM03-004 Owner: James Terrill Created: 01-JUL-03 12.00.00.000000000 AM Modified: 01-JUL-03 12.00.00.000000000 AM Classification: Norton |
SYMSA1028 |
Win32 Device Drivers Communication Vulnerabilities |
Advisory Status |
CLOSED |
| Summary |
A vulnerability has been discovered in Norton AntiVirus that can cause the host system to crash.
--> |
| Affected Products |
Components AffectedNAV 2002, 2003
|
| Issues |
DescriptionA vulnerability has been discovered in the Auto-protect component of Norton AntiVirus. Users with access to a system can craft a buffer, send it to Auto-Protect and cause the system to crash. Exploit code has been created as a proof on concept for this vulnerability. Mitigating the risk - Microsoft Windows systems ship with the guest user account activated. It is recommended that the system administrator or user disable or at least password protect this account. Some level of system access is required to exploit the vulnerability. By restricting access to the system running vulnerable code will substantially reduce the risk from this and many other vulnerabilities. Mitigation Symantec ResponsePatches that address this vulnerability are available for Symantec AV 8.01 build 446, Symantec AV 8.1 build 825, NAVCE 7.61 build 46a and NAVCE 7.61 build 50. Note: Symantec AV 8.01 build 457 and Symantec AV 8.11 build 314 and later have incorporated this fix and do not need to be patched. Installing the patchTwo versions of the patch are available for each of Symantec AV versions 8.01 build 446, Symantec AV 8.1 build 825, NAVCE 7.61 build 46a and NAVCE 7.61 build 50. For Windows 95, 98 and Me, use the version whose file name ends with "Win9x.zip." For Windows NT, 2000, XP, and 2003 servers and clients, use the version whose file name ends with "only.zip." The patch consists of a single executable to be run on each computer. Note: For Windows NT, 2000, XP, and 2003, you must be logged in as the local administrator account to apply the patch. Patches for Symantec AV 8.01 build 446:NAVAP-Patch8.01b446_only.zip NAVAP-Patch8.01b446_only-Win9x.zip Patches for Symantec AV 8.1 build 825:NAVAP-Patch8.1b825_only.zip NAVAP-Patch8.1b825_only-Win9x.zip Patches for NAVCE 7.61 build 50:NAVAP-Patch7.6b50_only.zip NAVAP-Patch7.6b50_only-Win9x.zip Patches for NAVCE 7.61 build 46a:NAVAP-Patch7.6b46a_only.zip NAVAP-Patch7.6b46a_only-Win9x.zip Note: If you have a version of Symantec AV or NAVCE that is not one of the specific builds listed, you cannot install the patch. For information on obtaining the specified builds, read the document How to obtain an update or an upgrade for your Symantec corporate product Acknowledgements References Additional DataLegacy ID: SYM03-006 Owner: James Terrill Created: 08-AUG-03 12.00.00.000000000 AM Modified: 08-AUG-03 12.00.00.000000000 AM Classification: Norton |
SYMSA1030 |
Symantec Norton Internet Security (NIS) Blocked Site Return Messages Not Properly Validated |
Advisory Status |
CLOSED |
| Summary |
A security group, The Digital Pranksters, reported an issue they discovered in Symantec's Norton Internet Security product. The URL in the return message from a site on the blocked list in the Norton Parental Control feature can allow an unauthorized script to run on the client system. --> |
| Affected Products |
Components AffectedSymantec's Norton Internet Security 2003
|
| Issues |
DescriptionSymantec's Norton Internet Security blocks inappropriate web content to help parents keep their children safe from inappropriate material while online. The Norton Parental Control blocks access to newsgroups and Web sites that may not be suitable for children. When a link is accessed or followed to one of the sites on the blocked list, Norton Internet Security returns a message stating that the site is restricted and has been blocked. The returned message includes the URL of the restricted site and is presented in a separate browser window Norton Internet Security opens on the client system. Digital Pranksters reported that they were able to supply a URL from a blocked site that contained an additional unauthorized script embedded in the URL. This script displayed in the blocked access message window on the client system. Mitigation Symantec ResponseSymantec has verified this issue. There is a bug in the way Norton Internet Security is validating the content it returns in the informational page. This is being fixed and will be forthcoming in a future LiveUpdate to Norton Internet Security products.
Acknowledgements Symantec takes the security and proper functionality of our products very seriously. Symantec appreciates the coordination of Digital Pranksters security team in identifying and providing details of this area of concern as well as working closely with Symantec to properly address the issue References Additional DataLegacy ID: SYM03-007 Owner: James Terrill Created: 27-OCT-03 12.00.00.000000000 AM Modified: 27-OCT-03 12.00.00.000000000 AM Classification: Norton |
SYMSA1037 |
Symantec Norton Internet Security and Norton AntiSpam Remote Access Vulnerability |
Advisory Status |
CLOSED |
| Summary |
NGSsoftware notified Symantec of a security vulnerability NGSsoftware had found in the Symantec Norton Internet Security and Symantec Norton AntiSpam 2004. If properly exploited this vulnerability could allow remote execution of arbitrary code on a targeted system resulting in possible system compromise. --> |
| Affected Products |
Consumer:
|
| Issues |
DetailsSymantec was alerted to remote access vulnerabilities that NGSsoftware discovered while evaluating Symantec Norton Internet Security 2004 and Symantec Norton AntiSpam 2004. Symantec Norton Internet Security and Symantec Norton AntiSpam 2004 contain ActiveX components that do not properly validate/parse external input. A malicious individual could potentially exploit these weaknesses to launch a local application on the target system and possibly run arbitrary code of their choice on the local system with elevated privileges. The Common Vulnerabilities and Exposures (CVE) initiative has assigned the following Candidate names to these issues: Mitigation Symantec ResponseSymantec verified the issue reported by NGSsoftware for Symantec Norton AntiSpam 2004 and Symantec Norton Internet Security 2004 and released a fix via Symantec LiveUpdate. Additional review determined the issue NGSsoftware reported for Symantec Norton Internet Security 2004 also impacted additional versions of Symantec Client Firewall products. Symantec product engineers developed fixes for the issue and released patches for all impacted products through Symantec LiveUpdate and technical support channels.
Customers running Symantec Client Firewall or Symantec Client Security should download and apply patches obtained through their appropriate support channels. Acknowledgements Symantec appreciates the cooperation of Mark Litchfield and the NGSsoftware research team in identifying these issues References Additional DataLegacy ID: SYM04-005 Owner: James Terrill Created: 19-MAR-04 12.00.00.000000000 AM Modified: 19-MAR-04 12.00.00.000000000 AM Classification: Norton |
SYMSA1043 |
Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability |
Advisory Status |
CLOSED |
| Summary |
OverviewLAC (Little eArth Corporation, Ltd) notified Symantec of a security issue they discovered in an ActiveX control used by Symantec Norton AntiVirus 2004. If properly exploited this vulnerability could allow remote execution of code residing on the local system with privileges of the logged on user, launch of unauthorized popups or a denial of service (DoS) against the Symantec Norton AntiVirus application on the targeted system. --> |
| Affected Products |
Affected ComponentsSymantec Norton AntiVirus 2004
|
| Issues |
DetailsLAC notified Symantec of a vulnerability in an ActiveX control used in Symantec Norton AntiVirus 2004. The ActiveX control does not properly verify/validate external input. A malicious individual could potentially exploit this control to launch arbitrary executables of the attacker's choice with user privileges. The vulnerability could also be used to launch an unauthorized URL (pop-up) on the system; or, create a DoS situation causing the Symantec Norton AntiVirus application to freeze. The Common Vulnerabilities and Exposures (CVE) initiative has assigned CVE Candidate name CAN-2004-0487 to this issue. Mitigation Symantec ResponseSymantec verified the issues LAC reported in Symantec Norton AntiVirus 2004. Symantec product engineers have developed a fix and released patches for all impacted product versions through Symantec's LiveUpdate.
Symantec is not aware of any active exploits for or customer impact from this issue. Acknowledgements Symantec appreciates the cooperation of Yuu Arai and the Little eArth Corporation security research team in identifying these issues References Additional DataLegacy ID: SYM04-009 Owner: James Terrill Created: 20-MAY-04 12.00.00.000000000 AM Modified: 20-MAY-04 12.00.00.000000000 AM Classification: Norton |
SYMSA1049 |
Symantec Norton AntiVirus MS-DOS Reserved Device Name Handling |
Advisory Status |
CLOSED |
| Summary |
Symantec Norton AntiVirus consumer products do not effectively scan files with MS-DOS reserved device names once the file is resident on a user's system. This could potentially permit a malicious file disguised as an MS-DOS reserved device file to evade detection prior to attempted execution provided it can be downloaded to or physically placed on the targeted system. --> |
| Affected Products |
Affected ComponentsSymantec Norton AntiVirus 2003
|
| Issues |
DetailsiDefense reported a problem with Symantec's Norton AntiVirus consumer products in effectively scanning files and directories with MS-DOS reserved device names. Device names such as COM1, CON or LPT1 are reserved words, and not intended to be used as directory or file names. In fact, in the early MS-DOS and Win 3.x days, they could not be used as directory or file names. However there are currently ways to create directories or files in Win32 systems using reserved device names that could contain potentially malicious code. Symantec Norton AntiVirus consumer products currently do not consistently scan these types of files during automatic and manual scans. To get such a maliciously configured file on a target system, the attacker would need to either entice the targeted user to visit a location where the malicious file could be downloaded to the target system or have access to the target system to upload or transfer the malicious file. The Common Vulnerabilities and Exposures (CVE) initiative has assigned CVE Candidate name CAN-2004-0920 to this issue. Mitigation Symantec ResponseSymantec engineers have thoroughly tested this issue on all supported Symantec Norton AntiVirus consumer products. All Symantec Norton AntiVirus consumer products successfully scan incoming email files with MS-DOS reserved device names to detect malicious content. However, scanning of files with MS-DOS reserved device names residing on a system was inconsistent.Symantec engineers have developed a fix for this issue for Symantec Norton AntiVirus 2004 that is currently available through LiveUpdate. The fix is being incorporated into all other supported Symantec Norton AntiVirus versions and will be available through LiveUpdate when fully tested and released. Symantec is not aware of any active exploits for or customer impact from this issue.
Acknowledgements Symantec appreciates the cooperation of the iDefense research team in identifying this issue and coordinating with Symantec in the resolution process References Additional DataLegacy ID: SYM04-015 Owner: James Terrill Created: 05-OCT-04 12.00.00.000000000 AM Modified: 05-OCT-04 12.00.00.000000000 AM Classification: Norton |
SYMSA1050 |
Symantec Norton AntiVirus Auto-Protect Alert Notification Limited Denial of Service |
Advisory Status |
CLOSED |
| Summary |
Symantec is responding to a posting to the Bugtraq mailing list. The poster was able to create a VBS script that caused a minor denial of service by terminating the system tray icon for Symantec Norton AntiVirus as well as preventing the Auto-Protect pop-up alerts from displaying on the user's system. Risk ImpactMinimal to non-existent --> |
| Affected Products |
Affected ComponentsSymantec Norton AntiVirus (2003,2004, 2005)
|
| Issues |
DetailsA posting to the Bugtraq mailing list reported an issue with Symantec's Norton AntiVirus 2004. The poster reported that he could defeat the script blocking capability in Symantec Norton AntiVirus 2004 by running a malicious VBS script on the target system that kills the Auto-Protect capability. By running his script on the target system, the poster reported he was able to terminate the running Auto-Protect process, and kill the Auto-Protect feature of Symantec's Norton AntiVirus 2004 product. According to the poster, terminating the running Auto-Protect process could leave the targeted system vulnerable to additional malicious code attacks. Mitigation Symantec ResponseSymantec engineers have thoroughly tested this issue on all supported Symantec Norton AntiVirus consumer products.
Although this is a very low risk issue, Symantec takes the security and functionality of their products very seriously. Symantec product engineers are currently investigating alternatives to address this issue. A resolution to this minimal disruption for Symantec's 2005 product versions has been completed. The update can be obtained through technical support from this location.
Acknowledgements References Additional DataLegacy ID: SYM04-016 Owner: James Terrill Created: 10-NOV-04 12.00.00.000000000 AM Modified: 10-NOV-04 12.00.00.000000000 AM Classification: Norton |
SYMSA1054 |
Symantec Completes Update of Microsoft's Graphic Device Interface Component (gdiplus.dll) |
Advisory Status |
CLOSED |
| Summary |
Risk ImpactNone Reference Microsoft Security Bulletin MS04-028, Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution. Symantec did a thorough review of all products that install a Symantec version of the gdiplus.dll when this vulnerability was initially identified. --> |
| Affected Products |
Affected ComponentsSymantec Norton SystemWorks 2003, 2004, 2005
|
| Issues |
Of particular importance to Symantec products and Symantec customers is the portion of the MS04-028 bulletin that states "Not every program that installs this file is vulnerable to this issue because it may not use the gdiplus.dll file to process JPEG images. Even when the third-party application uses the gdiplus.dll file to process JPEG images it may not do so in a vulnerable way. For example if an application does not allow users to supply images for processing or performs additional validation on the images before processing, it may not be vulnerable." Mitigation Symantec customers who regularly run Symantec LiveUpdate should already be updated to the current gdiplus.dll in most affected products. However, the Symantec gdiplus.dll update requires a current version of Symantec Windows LiveUpdate to download and install properly on some of the affected products. The current version of Symantec Windows LiveUpdate is version 2.6 that is available for download from the Symantec technical support site at http://www.symantec.com/techsupp/files/lu/lu.html. To determine your version of Symantec LiveUpdate:
If you are running a version of Symantec LiveUpdate prior to v2.6, you should download Symantec Windows LiveUpdate v2.6 from the support site indicated above to upgrade your system to the latest release of Symantec Windows LiveUpdate.
Acknowledgements References Additional DataLegacy ID: SYM05-002 Owner: James Terrill Created: 18-JAN-05 12.00.00.000000000 AM Modified: 18-JAN-05 12.00.00.000000000 AM Classification: Norton |
SYMSA1058 |
Denial of Service in Symantec Norton AntiVirus AutoProtect |
Advisory Status |
CLOSED |
| Summary |
Symantec responded to two denial of service (DoS) issues identified in the AutoProtect functionality of the Symantec Norton AntiVirus consumer product. The Information-Technology Promotion Agency-Japan, IPA, reported one situation where a real time scan of a specific file type can cause a system crash, Blue Screen of Death (BSOD), with both Symantec Norton AntiVirus 2004 and 2005 Windows applications. This type of file, while not malicious on its own, could be maliciously introduced either remotely from outside the system through email or over http, or internally by an authorized user to disrupt service on a targeted system. Scanning specific file modifications using the “SmartScan” feature of AutoProtect in the Symantec Norton AntiVirus 2005 application can cause the other DoS issue reported by the Japan Computer Emergency Response team, JPCERT. Any malicious use of this DoS would require authorized access to the targeted system to implement. --> |
| Affected Products |
Affected ProductsSymantec Norton AntiVirus 2004
|
| Issues |
DetailsIssue One: CVEA CVE candidate number will be requested from The Common Vulnerabilities and Exposures (CVE) initiative. This advisory will be revised as required once the CVE candidate number has been assigned. This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. Mitigation Symantec ResponseSymantec product engineers confirmed both issues impacting Symantec’s Auto-Protect feature in Symantec Norton AntiVirus and have developed and released a patch for all impacted products through Symantec LiveUpdate. Customers running Automatic LiveUpdate should already be updated.
Symantec is unaware of any adverse customer impact from either of these issues Acknowledgements Symantec would like to thank Mr. Isamu Noguchi, who initially identified both issues, for reporting them to the Information-Technology Promotion Agency-Japan and JPCERT. Symantec further thanks IPA and JPCERT for providing the coordination while Symantec resolved the issues References Additional DataLegacy ID: SYM05-006 Owner: James Terrill Created: 28-MAR-05 12.00.00.000000000 AM Modified: 28-MAR-05 12.00.00.000000000 AM Classification: Norton |
SYMSA1076 |
Symantec Norton AntiVirus for Macintosh DiskMountNotify Local Privilege Escalation |
|||||||||||||||
Advisory Status |
CLOSED |
|||||||||||||||
| Summary |
Risk Impact
--> |
|||||||||||||||
| Affected Products |
|
|||||||||||||||
| Issues |
DetailsThe DiskMountNotify component of Symantec Norton AntiVirus for Macintosh does not set its execution path environment. A non-privileged user can change their execution path environment. If the user then executes the DiskMountNotify component, it will inherit the changed environment and use it to locate system commands. The DiskMountNotify is configured to run with System Administrative privileges (SUID) and is vulnerable to a potential Trojan horse attack. The Common Vulnerabilities and Exposures (CVE) initiative has assigned CVE Candidate CVE-2005-3270 to this issue. Mitigation Symantec ResponseA patch has been created and made available for all affected version of the product through Symantec LiveUpdate.
Symantec is not aware of any active attempts against or customers impacted by this issue. Acknowledgements Symantec thanks iDefense, for notification of this issue and coordinating disclosure as it was resolved References Additional DataLegacy ID: SYM05-020 Owner: James Terrill Created: 19-OCT-05 12.00.00.000000000 AM Modified: 19-OCT-05 12.00.00.000000000 AM Classification: Norton |
SYMSA1084 |
Symantec Norton Protected Recycle Bin Exposure |
|||||||||||||
Advisory Status |
CLOSED |
|||||||||||||
| Summary |
Norton SystemWorks contains a feature called the Norton Protected Recycle Bin, which resides within the Microsoft Windows Recycler directory. The Norton Protected Recycle Bin includes a directory called NProtect, which is hidden from Windows APIs. Files in the directory might not be scanned during scheduled or manual virus scans. This could potentially provide a location for an attacker to hide a malicious file on a computer. Risk Impact
--> |
|||||||||||||
| Affected Products |
|
|||||||||||||
| Issues |
DetailsThe NProtect directory is used to store temporary copies of files that the user has deleted or modified. This feature supplements the Windows Recycle Bin, creating a temporary backup of certain types of files that the Windows Recycle Bin does not back up. The Norton Protected Recycle Bin allows the user to recover these protected files if they are accidentally deleted.
Mitigation Symantec ResponseSymantec product engineers have developed and released an update for products affected by this exposure. The update is available through Symantec LiveUpdate by running a manual update. To manually update via Symantec LiveUpdate, users should:
This update will require a system reboot. Acknowledgements Symantec would like to thank Mark Russinovich of Sysinternals (www.sysinternals.com) and the F-Secure Blacklight team (www.f-secure.com/blacklight/) for their cooperation in working with us on this issue References Additional DataLegacy ID: SYM06-001 Owner: James Terrill Created: 10-JAN-06 12.00.00.000000000 AM Modified: 10-JAN-06 12.00.00.000000000 AM Classification: Norton |
SYMSA1106 |
Symantec Automated Support Assistant: Vulnerabilities in Support Tool ActiveX Control |
||||||||||||||
Advisory Status |
CLOSED |
||||||||||||||
| Summary |
Vulnerabilities were reported in a Symantec-developed ActiveX control, installed with some of Symantec’s consumer products and as a part of Symantec’s technical support troubleshooting tools. Exploitation of these issues could possibly lead to unauthorized information disclosure or potentially allow arbitrary code execution in the context of the user’s browser. However, successful exploitation requires specific conditions. Severity
--> |
||||||||||||||
| Affected Products |
Supported Product(s)
|
||||||||||||||
| Issues |
DetailsSymantec was alerted to a stack overflow and information disclosure vulnerabilities that Next Generation Security Research (NGSS) discovered in a Symantec-developed ActiveX control, installed as a part of Symantec’s Automated Support Assistant and with some of Symantec’s consumer products (indicated above). This ActiveX control failed to properly validate external input. This failure could potentially result in a browser crash or, possibly unauthorized use of methods allowing access to system information as well as a stack overflow with the potential for malicious code execution in the context of the user’s browser. This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. The CVE identifier assigned to this issue is CVE-2006-5403 Mitigation Symantec ResponseSymantec product engineers have developed and released solutions for this issue through Symantec's LiveUpdate and other venues.
Symantec product engineers have upgraded the current vulnerable component on the Symantec support website so users will be able to download a non-vulnerable version of the Automated Support Assistant. MitigationSymantec Security Response has also developed a removal tool to assist in removing legacy versions of the at risk control. The removal tool is located here Best PracticesAs part of normal best practices, Symantec strongly recommends a multi-layered approach to security:
Acknowledgements Symantec thanks John Heasman of Next Generation Security Research for reporting this finding to us and for excellent coordination while resolving this issue. References Additional DataLegacy ID: SYM06-019 Owner: James Terrill Created: 05-OCT-06 12.00.00.000000000 AM Modified: 05-OCT-06 12.00.00.000000000 AM Classification: Norton |
SYMSA1112 |
Stack Overflow in Third-Party ActiveX Controls affects Multiple Vendor Products Including Some Syman |
||||||||||
Advisory Status |
CLOSED |
||||||||||
| Summary |
Vulnerabilities were identified in third-party trouble-shooting ActiveX controls, developed by SupportSoft, www.supportsoft.com . Two of these controls were signed, shipped and installed with the identified versions of Symantec's consumer products and as part of the Symantec Automated Support Assistant support tool. The vulnerability identified in the Symantec shipped controls could potentially result in a stack overflow requiring user interaction to exploit. If successfully exploited this vulnerability could potentially compromise a user's system possibly allowing execution of arbitrary code or unauthorized access to system assets with the permissions of the user's browser. Severity
--> |
||||||||||
| Affected Products |
|
||||||||||
| Issues |
DetailsSymantec was initially alerted by Next Generation Security Software (NGSS), to stack overflow and unauthorized access vulnerabilities identified in two SupportSoft ActiveX controls, SmartIssue tgctlsi.dll and ScriptRunner tgctlsr.dll, that Symantec signed and shipped with some of Symantec's 2006 consumer products and used by the Symantec Automated Support Assistant support tool Symantec provides on its consumer support site. These SupportSoft ActiveX components did not properly validate external input. This failure could potentially lead to unauthorized access to system resources or the possible execution of malicious code with the privileges of the user's browser, resulting in a potential compromise of the user's system. A CVE Candidate CVE-2006-6490 has been assigned. This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.
Mitigation Symantec ResponseSymantec worked closely with SupportSoft to ensure updates were quickly made available for the identified controls. SupportSoft has posted a Security Bulletin for the controls Symantec uses and controls used in other products on their support site, www.supportsoft.com.
Symantec recommends customers always ensure they have the latest updates to protect against threats.
MitigationSymantec Security Response is releasing an AntiVirus Bloodhound definition Bloodhound.Exploit.119, a heuristic detection and prevention for attempts to exploit these vulnerable controls. Virus definitions containing this heuristic will be available through Symantec LiveUpdate or Symantec's Intelligent Updater. Acknowledgements Symantec has coordinated very closely with SupportSoft to help ensure that all additional affected vendor customer bases has been provide with information concerning affected controls and updates to address the vulnerability. Symantec wants to thank Mark Litchfield of NGS Software Ltd. for the initial identification and notification of this issue and for the excellent, in-depth coordination with both Symantec and SupportSoft while resolving the issue. Additionally, this issue was independently identified by the analysts at CERT , in CERT Vulnerability Note VU#441785, who reported their findings to and worked closely with both Symantec and SupportSoft through to resolution and by Peter Vreugdenhil, working through iDefense who coordinated with Symantec as we resolved the issue References Additional DataLegacy ID: SYM07-002 Owner: James Terrill Created: 22-FEB-07 12.00.00.000000000 AM Modified: 22-FEB-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1114 |
Multiple Norton Ghost, Norton Save & Recovery, Symantec LiveState Recovery, and Symantec BackupExec |
||||||||||||||
Advisory Status |
CLOSED |
||||||||||||||
| Summary |
Two vulnerabilities have been identified in Norton Ghost, Norton Save & Recovery, LiveState Recovery and BackupExec System Recovery. Risk Impact
--> |
||||||||||||||
| Affected Products |
Vulnerable Products
|
||||||||||||||
| Issues |
DetailsScheduled backups of local disks saved to remote network shares saves login credentials, for the remote share, into the application directory with read access set for everyone.
Mitigation Symantec ResponseSymantec has released updates for all affected product version currently supported by Symantec. These updates are available through LiveUpdate. Acknowledgements Symantec would like to thank Pravus for reporting this issue to iDefense Labs. Symantec would like to thank iDefense Labs for reporting these issues to Symantec, and working with us on the resolution References Additional DataLegacy ID: SYM07-004 Owner: James Terrill Created: 26-APR-07 12.00.00.000000000 AM Modified: 26-APR-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1116 |
Symantec COM object security bypass |
||||||||||
Advisory Status |
CLOSED |
||||||||||
| Summary |
A design error in an ActiveX control used by Norton AntiVirus could potentially be exploited by a malicious web site. A successful exploit could lead to remote code execution. Risk Impact
--> |
||||||||||
| Affected Products |
|
||||||||||
| Issues |
DetailsSymantec was notified by iDefense that a design error in NAVOPTS.DLL, an ActiveX control used by Norton AntiVirus, could potentially allow an attacker to crash the control if the end user visits a malicious web site. A successful exploit of NAVOPTS.DLL could then allow the attacker to access other Symantec ActiveX controls, even if they are not marked safe for scripting, possibly leading to remote arbitrary code execution in the context of the user's browser. This issue is a candidate for inclusion in the Common Vulnerabilities and Exposures (CVE) list (http://cve.mitre.org), which standardizes names for security problems. The CVE initiative has assigned CVE-2006-3456 to this issue Mitigation Symantec ResponseSymantec product engineers have determined that the issue affects the Norton consumer products listed in the table above. Product updates to correct the problem are available through LiveUpdate.
Symantec is not aware of any customers impacted by this issue, or of any attempts to exploit the issue.
Best PracticesAs part of normal best practices, Symantec strongly recommends a multi-layered approach to security:
Acknowledgements Symantec would like to acknowledge Peter Vreugdenhil, working with the iDefense Vulnerability Contributor Program (http://www.idefense.com), for reporting this issue and coordinating with us on the response References Additional DataLegacy ID: SYM07-005 Owner: James Terrill Created: 09-MAY-07 12.00.00.000000000 AM Modified: 09-MAY-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1117 |
Symantec Norton Personal Firewall 2004 ActiveX Control Buffer Overflow |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
An ActiveX control used by Norton Personal Firewall 2004 and Norton Internet Security 2004 contains a buffer overflow vulnerability. Risk Impact
--> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
DetailsCERT notified Symantec that a buffer overflow exists in an ActiveX Control used by Norton Personal Firewall. The error occurs in the Get() and Set() functions used by ISAlertDataCOM, which is part of ISLALERT.DLL. A successful exploit of this vulnerability could potentially allow the remote execution of code on a vulnerable system, with the rights of the logged-in user. This issue is a candidate for inclusion in the Common Vulnerabilities and Exposures (CVE) list (http://cve.mitre.org), which standardizes names for security problems. The CVE initiative has assigned CVE-2007-1689 to this issue Mitigation Symantec ResponseSymantec product engineers have determined that the issue affects Norton Personal Firewall and Norton Internet Security 2004 only. Product updates to correct the problem are available through LiveUpdate. How to obtain the updateNorton Internet Security and Norton Personal firewall 2004 users who normally run manual LiveUpdate to obtain product updates can also obtain this update through the same process. Run manual LiveUpdate as follows:
If you have not previously installed all available product updates, you will need to obtain those updates first. You will need to modify your LiveUpdate settings to connect to the archive LiveUpdate server to obtain the previous product updates. MitigationSymantec has released IPS signatures for the Symantec products listed below, to detect attempts to exploit this vulnerability. Best PracticesAs part of normal best practices, Symantec strongly recommends a multi-layered approach to security:
Acknowledgements Symantec would like to thank Will Dormann of the CERT Coordination Center (http://www.cert.org/certcc.html) for reporting this issue and coordinating with us on the response. References Additional DataLegacy ID: SYM07-007 Owner: James Terrill Created: 16-MAY-07 12.00.00.000000000 AM Modified: 16-MAY-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1131 |
Symantec ActiveX Control Input Validation Error |
||||||||||||||
Advisory Status |
CLOSED |
||||||||||||||
| Summary |
An input validation error in two ActiveX controls used by Norton AntiVirus, Norton Internet Security, and Norton System Works could allow an attacker to execute code on the target system. Risk Impact
--> |
||||||||||||||
| Affected Products |
Affected Products
|
||||||||||||||
| Issues |
DetailsSymantec was notified that two ActiveX controls supplied by NAVCOMUI.DLL contain an input validation error for two properties of the controls. This error could allow an attacker to crash Internet Explorer, or possibly run arbitrary code with the rights of the logged in user. The Common Vulnerabilities and Exposures (CVE) initiative has assigned CVE Candidate CVE-2007-2955 to this issue. Mitigation Symantec responseSymantec engineers have confirmed that the vulnerability in the products listed in the Affected Products table above. Updates for affected products are available through LiveUpdate. MitigationSymantec Security Response has released Bloodhound.Exploit.148 to detect and block attempts to exploit this vulnerability. This detection is available in virus definitions dated 08-09-2007 and later. How to Obtain the UpdateSymantec Norton product users who regularly launch and run LiveUpdate should already have received an updated (non-vulnerable) version of NAVCOMUI.DLL.
Best PracticesSymantec recommends any affected customers update their product immediately to protect against potential attempts to exploit this vulnerability. As part of normal best practices, Symantec recommends the following:
Acknowledgements Symantec would like to thank Carsten Eiram, Secunia Research for reporting this issue and coordinating with us on the response References Additional DataLegacy ID: SYM07-021 Owner: James Terrill Created: 09-AUG-07 12.00.00.000000000 AM Modified: 09-AUG-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1140 |
Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh Local Elevation of Privilege |
|||||||||||||||
Advisory Status |
CLOSED |
|||||||||||||||
| Summary |
A feature of Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh could be used by members of the group admin to execute code as the root user (uid 0) on the local system. Risk Impact
--> |
|||||||||||||||
| Affected Products |
|
|||||||||||||||
| Issues |
DetailsAn executable used by the Mount Scan feature of Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh runs with root access. A member of group admin could replace this executable with code of their choice, and gain user root access. This issue is a candidate for inclusion in the Common Vulnerabilities and Exposures (CVE) list (http://cve.mitre.org), which standardizes names for security problems. CVE-2007-5829 has been assigned to this exposure. Mitigation Symantec ResponseSymantec engineers have verified that this issue exists in the products listed above. However, any potential attempt to exploit the issue will fail if Mount Scanning is disabled, or if Mount Scanning is configured to run without showing progress. MitigationCustomers who have not updated to a non-vulnerable version or applied the application extension have the following options: Best PracticesSymantec recommends any affected customers apply one of the mitigation steps to protect against potential attempts to exploit this issue. As part of normal best practices, Symantec recommends the following:
Acknowledgements Symantec would like to thank William Carrel for reporting this issue. References Additional DataLegacy ID: SYM07-028 Owner: James Terrill Created: 01-NOV-07 12.00.00.000000000 AM Modified: 01-NOV-07 12.00.00.000000000 AM Classification: Norton |
SYMSA1150 |
Symantec AutoFix Support Tool ActiveX Control Vulnerabilities |
||||||||||||||||||||
Advisory Status |
CLOSED |
||||||||||||||||||||
| Summary |
Two vulnerabilities reported in an ActiveX control used by the Symantec AutoFix Tool could potentially allow arbitrary code execution in the context of the user’s browser. Successful exploitation requires user interaction. SeverityLow
--> |
||||||||||||||||||||
| Affected Products |
Affected Products
Note:The affected ActiveX control is shipped only with the consumer products noted above. The control may also have been installed during an online chat session with a member of Symantec’s Consumer Technical Support team. See How to Obtain an Updated AutoFix Tool, below, for information on the update.
|
||||||||||||||||||||
| Issues |
DetailsIDefense notified Symantec of two vulnerabilities in an ActiveX control (SYMADATA.DLL) used to troubleshoot Symantec consumer products. These issues are candidates for inclusion in the Common Vulnerabilities and Exposures (CVE) list (http://cve.mitre.org), which standardizes names for security problems. CVE has assigned CVE-2008-0312 to the buffer overflow, and CVE-2008-0313 to the launch process design error.
Mitigation Symantec ResponseSymantec engineers have developed and released updates to address both of these vulnerabilities, as described under How to Obtain the Update.The affected ActiveX control is digitally signed and site locked so it can only be scripted from a trusted domain. To successfully exploit either vulnerability, an attacker would need to be able to masquerade as the trusted Symantec website, such as through a Cross Site Scripting attack or DNS poisoning. The user must also be enticed to visit the malicious website from which the attack would be launched. This type of attack is often achieved by sending email or instant message containing a link to the malicious site, and persuading the recipient to click on the link. The overall severity of these vulnerabilities is considered to be low because of the indirect nature of the attack vector, and the reliance on user interaction to accomplish a successful exploit. Symantec is not aware of any customers impacted by this issue, or of any attempts to exploit the issue. MitigationSymantec has released IPS signatures for Norton firewall products, to detect and block attempts to exploit the buffer overflow (BID 28507). In addition, Symantec Security Response has released a Bloodhound detection for all Symantec antivirus programs, to detect and block attempts to exploit the launch process design error. These signatures are available by running LiveUpdate.How to Obtain IPS and Virus Definition UpdatesSymantec Norton product users who regularly launch and run LiveUpdate should already have received the IPS signatures and virus definitions. However, to ensure all available updates have been applied, users can manually launch and run LiveUpdate in Interactive mode as follows:
How to Obtain an Updated AutoFix ToolAn updated (non-vulnerable) version of the AutoFix tool will be automatically installed if customers participate in an online Chat session with Symantec Technical Support.Customers can also download and install an updated AutoFix Tool here: http://www.symantec.com/techsupp/asa/ctrl/SymADataWeb.msi Best PracticesAs a part of normal best practices, users should keep vendor-supplied patches for all software and operating systems up-to-date. Symantec recommends any affected customers update their product immediately to protect against potential attempts to exploit these vulnerabilities.Additional best practices include:
Acknowledgements Symantec would like to thank Peter Vreugdenhill and an anonymous finder, working with the IDefense VCP (http://labs.idefense.com/vcp/) for reporting these issues, and coordinating with us on the response. References Additional DataLegacy ID: SYM08-009 Owner: James Terrill Created: 02-APR-08 12.00.00.000000000 AM Modified: 02-APR-08 12.00.00.000000000 AM Classification: Norton |
SYMSA1182 |
Norton AntiVirus and Symantec Client Security Email Denial of Service Vulnerability |
|||||||||||||||||||||||||
Advisory Status |
CLOSED |
|||||||||||||||||||||||||
| Summary |
Norton AntiVirus and Symantec Client Security are susceptible to an email denial of Service (DoS) attack which could be triggered by a specially crafted email message. --> |
|||||||||||||||||||||||||
| Affected Products |
|
|||||||||||||||||||||||||
| Issues |
Risk Impact Low
Mitigation Details Next Generation Security Software notified Symantec that a specially crafted email could potentially create a Denial of Service (DoS) condition on an end user system. The malicious message would require a significantly longer than normal time to process, which could cause the client system to lose connection with the mail server. The email client will try to download the message again the next time it connects to the mail server, and again lose connection. This cycle would be repeated until the malicious message was deleted from the mail server.
Symantec Response Symantec has confirmed that this issue exists in the products listed in the Affected Products table above. The vulnerability can be exploited only if the optional Internet Email Scanning feature is enabled on the user’s system.
Mitigation Internet Email Scanning is an optional feature which can disabled if it is not being used. Disabling this feature prevents it from being exploited through this vulnerability.
Updating Norton products Norton product users who launch and run LiveUpdate regularly have already received an update to address this issue. However, to ensure all available updates have been applied, users can manually launch and run LiveUpdate in interactive mode as follows:
Best Practices As part of normal best practices, Symantec strongly recommends a multi-layered approach to security:
Acknowledgements Symantec thanks Mark Litchfield from Next Generation Security Software (http://www.ngssoftware.com/) for reporting this issue, and coordinating with us on the response. References SecurityFocus, http://www.securityfocus.com, has assigned BID 34670 to this issue Additional DataLegacy ID: SYM09-012 Owner: James Terrill Created: 26-AUG-09 12.00.00.000000000 AM Modified: 26-AUG-09 12.00.00.000000000 AM Classification: Norton |
SYMSA1211 |
Norton Mobile Security Beta Information Disclosure |
||||||||
Advisory Status |
CLOSED |
||||||||
| Summary |
Symantec’s Norton Mobile Security Beta for Android logs information to the Android Smartphone system logs. Inadvertent or malicious access to logs could allow potentially sensitive user and application information to be revealed. --> |
||||||||
| Affected Products |
|
||||||||
| Issues |
Severity Medium
Mitigation Details Android system logs where Norton Mobile Security Beta sensitive information is stored. Some applications downloaded to an Android Smartphone may be able to gain unnecessary and/or unauthorized read/write access permission to device logs without the consent or knowledge of the device owner.
Symantec Response Symantec product engineers have developed and released a solution. Symantec Mobile Security Beta for Android users should updated to the latest release available through normal update procedures.
Best Practices As part of normal best practices, Symantec strongly recommends:
Acknowledgements Symantec thanks Tim Wyatt with Lookout Mobile Security for reporting their finding and coordinating closely with Symantec in resolving the issue. References Security Focus, http://www.securityfocus.com, has assigned a Bugtraq ID (BID) 44767 to this issue for inclusion in the Security Focus vulnerability database. Additional DataLegacy ID: SYM10-011 Owner: James Terrill Created: 11-NOV-10 12.00.00.000000000 AM Modified: 11-NOV-10 12.00.00.000000000 AM Classification: Norton |
SYMSA1237 |
Symantec Updates Gear Driver for Local Access Denial of Service |
|||||||||||||
Advisory Status |
CLOSED |
|||||||||||||
| Summary |
Symantec has provided updates for the Gear Software driver ‘GEARAspiWDM.sys’ in affected versions of supported Symantec products. This update addresses a possible local access denial of service system crash. --> |
|||||||||||||
| Affected Products |
|
|||||||||||||
| Issues |
Medium CVSS2 Base Score: 4.4 Impact 6.9, Exploitability 2.7 CVSS2 Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:C) Exploit Publicly Available: Yes Mitigation Details Symantec is aware of a local denial of service as a result of the Gear Software CD DVD filter driver GEARAspiWDM.sys improper validation of external input. The Gear Software driver ships with Symantec products identified in the affected products table above. Successful exploitation would require local authorized access to the targeted system or interaction with an authorized local user to upload and run malicious code on their system.
Symantec Response Symantec engineers confirmed the issue existing in the Gear Software driver version shipped with the listed products. Gear Software released a driver update to address this issue. Symantec recommends all affected product customers download and apply the update identified above to prevent threats of this nature. Symantec is not aware of any exploitation of, or adverse customer impact from this issue.
Obtaining the Update Norton 360 and Symantec System Recovery customers running LiveUpdate in automatic mode have already received an updated version of the affected driver. However, to ensure all available updates have been applied, users can run a manual (interactive) LiveUpdate as follows:
Customers running other impacted products should upgrade to the recommended product version indicated in the Affected Products table or download and apply the latest Gear driver from Gear Software’s web site:
Backup Exec System Recovery 201 Acknowledgements References Security Focus, http://www.securityfocus.com, has assigned Bugtraq ID (BID) 47822 to this issue in the Security Focus vulnerability database. CVE: This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. CVE-2011-3477 has been assigned to this issue. Additional DataLegacy ID: SYM11-014 Owner: James Terrill Created: 09-NOV-11 12.00.00.000000000 AM Modified: 09-NOV-11 12.00.00.000000000 AM Classification: Norton |
SYMSA1384 |
Norton Mobile Security for Android Multiple Security Issues |
||||||||||
Advisory Status |
CLOSED |
||||||||||
| Summary |
Symantec has addressed issues in Norton Mobile Security for Android where an attacker with sufficient knowledge of source code logic could cause a crash, extract sensitive system information, and/or add an arbitrary URL to the application's whitelist. --> |
||||||||||
| Affected Products |
|
||||||||||
| Issues |
Mitigation Acknowledgements
References Additional DataLegacy ID: SYM16-019 Owner: James Terrill Created: 01-NOV-16 12.00.00.000000000 AM Modified: 01-NOV-16 12.00.00.000000000 AM Classification: Norton |
||||||||||
SYMSA1386 |
Norton App Lock Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has addressed an issue where on some Android devices, Norton App Lock could have been bypassed, which could have allowed locked applications to be opened. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation Norton App Lock for Android has been updated to fix this issue. Customers will either be notified that their product has been auto-updated or will be notified that an update is available for them to install, depending on configuration Acknowledgements
References Additional DataLegacy ID: SYM16-022 Owner: James Terrill Created: 30-NOV-16 12.00.00.000000000 AM Modified: 30-NOV-16 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1394 |
Norton Download Manager DLL Loading |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address a DLL loading vulnerability detected in the Norton Download Manager for affected products --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation Norton Download Manager is not updated though Liveupdate. Customers first download Norton Download Manager during the initial install of a Norton security product and it is normally a run-once application to manage the download and install of the selected Norton product. There is some potential that users may need to run a previously downloaded version of Norton Download Manager in the following scenarios:
The upgrade solution for impacted customers is to:
Customers and users who want to download a trial version of a Norton security or Norton Family product can visit the Norton website. Once there, navigate to PRODUCT & SERVICES and select Free Trials. Customers who want to download a licensed Norton security or Norton Family product can log into their Norton account and click on Download.
*Affected Norton Family Products
Best Practices Symantec recommends the following measures to reduce the Acknowledgements
References Additional DataLegacy ID: SYM17-001 Owner: James Terrill Created: 17-JAN-17 12.00.00.000000000 AM Modified: 17-JAN-17 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1415 |
Norton Remove and Reinstall DLL Preloading |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue in the Norton Remove and Reinstall product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue was validated by the product team engineers. A Norton Remove & Reinstall update, version 4.4.0.58, has been released which addresses the aforementioned vulnerability. Note that Norton Remove & Reinstall’s latest release and patches are available to customers through normal support channels or can be downloaded directly from the following URL: To determine if your version of Norton Remove & Reinstall is susceptible to this vulnerability, please perform the following actions:
At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues.
Best Practices Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: SYM17-009 Owner: James Terrill Created: 26-SEP-17 12.00.00.000000000 AM Modified: 26-SEP-17 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1422 |
Install Norton Security Certificate Spoof |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address one issue in the Install Norton Security (INS) product which occurs when downloading Norton for Mac. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue was validated by the product team engineers. An Install Norton Security (INS) update, version 7.6, has been released which addresses the aforementioned issue. To apply the fix, please uninstall the previous version of Install Norton Security and then download and install the updated version. Note that you can access the updated Install Norton Security at the following URL: At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues.
BEST PRACTICESSymantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: SYM17-014 Owner: James Terrill Created: 21-NOV-17 12.00.00.000000000 AM Modified: 21-NOV-17 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1424 |
Symantec Norton Family Android App Multiple Issues |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address two issues in the Symantec Norton Family Android App. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation These issues were validated by the product team engineers. A Norton Family Android App update, version 4.4.1.10, has been released which address the aforementioned issues. Note that the latest Symantec Norton Family Android App release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. BEST PRACTICESSymantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: SYM17-015 Owner: James Terrill Created: 13-DEC-17 12.00.00.000000000 AM Modified: 13-DEC-17 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1431 |
Norton App Lock Authentication Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address one issue in the Norton App Lock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.3.0.13, has been released which addresses the aforementioned issue. Note that the latest Symantec Norton App Lock release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. Additional note: The Norton App Lock version 1.3.0.13 is fully vetted and functional on tested devices including Android OS on Samsung, Redmi, and Xiomi. However, the fix is not functional on the Lenovo K3 device due to an inherent issue in the device itself. Symantec has opened a support case for this issue and it has been confirmed from Lenovo that they are not going to provide any fix for this issue due to the age of the device. The support case can be referenced via the following link: Symantec has confirmed that this particular issue does not affect the latest Lenovo devices.
BEST PRACTICESSymantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: SYM18-001 Owner: James Terrill Created: 26-MAR-18 12.00.00.000000000 AM Modified: 26-MAR-18 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1444 |
Norton Core Command Injection |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address one issue in the Norton Core product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton Core update, v237, has been released which addresses the aforementioned issue. Note that Norton Core updates are received to devices automatically via firmware updates to the router. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. BEST PRACTICES Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 30-APR-18 12.00.00.000000000 AM Modified: 30-APR-18 12.00.00.000000000 AM Classification: Norton |
|||||||||
SYMSA1453 |
Norton App Lock Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton App Lock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.3.0.329, has been released which addresses the aforementioned issue. Note that the latest Symantec Norton App Lock release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 07-JUN-18 12.00.40.000000000 PM Modified: 13-JUN-18 08.01.11.000000000 AM Classification: Norton |
|||||||||
SYMSA1455 |
Norton App Lock Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton App Lock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.3.0.332, has been released which addresses the aforementioned issue. Note that the latest Symantec Norton App Lock release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 10-JUL-18 05.44.26.000000000 AM Modified: 19-JUL-18 12.10.08.000000000 PM Classification: Norton |
|||||||||
SYMSA1459 |
Norton Utilities, Norton Power Eraser & Symdiag - DLL Preloading |
|||||||||||||||||
Advisory Status |
CLOSED |
|||||||||||||||||
| Summary |
Symantec has released an update to address issues in the Norton Utilities, Norton Power Eraser, and SymDiag products. --> |
|||||||||||||||||
| Affected Products |
|
|||||||||||||||||
| Issues |
Mitigation These issues were validated by product team engineers. A set of updates, Norton Utilities 16.0.3.44, Norton Power Eraser 5.3.0.24, and SymDiag 2.1.242, have been released which address the aforementioned issues. The latest releases and patches are available to customers through normal support channels or can be downloaded directly from the Norton.com website for Norton Utilities and Norton Power Eraser; for SymDiag, they can be downloaded by following the instructions in the following technote: https://support.symantec.com/en_US/article.TECH170752.html **Note: The latest updates addressing these issues apply to Windows versions 8 and higher. For users running Windows 7, the listed issues may still manifest and as such, users are encouraged to update their operating systems to a more recent version. These issues are actually common in the Windows operating system and the product teams have taken steps to circumvent these particular security flaws. For additional information on this particular Windows vulnerability, please access the following link from the MSFT support website: At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 15-AUG-18 02.01.40.000000000 PM Modified: 30-AUG-18 12.00.48.000000000 PM Classification: Norton |
|||||||||||||||||
SYMSA1460 |
Norton Identity Safe Privilege Escalation |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Identity Safe for Android product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue was validated by product team engineers. A Norton Identity Safe for Android update, version 5.3.0.976, has been released which addresses the aforementioned issue. The latest releases and patches are available to customers through normal support channels or can be updated directly from the Google Play store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 22-AUG-18 12.15.13.000000000 PM Modified: 29-AUG-18 10.43.04.000000000 AM Classification: Norton |
|||||||||
SYMSA1470 |
Norton Password Manager XSS |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android (formerly Norton Identity Safe) product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton Password Manager for Android (formerly Norton Identity Safe) update, version 6.1.0.1045, has been released which addresses the aforementioned issue. Note that the latest Norton Password Manager for Android release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 30-NOV-18 06.40.33.000000000 AM Modified: 06-DEC-18 06.00.27.000000000 AM Classification: Norton |
|||||||||
SYMSA1473 |
Norton App Lock Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton App Lock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.4.0.445, has been released which addresses the aforementioned issue. Note that the latest Symantec Norton App Lock release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements CVE-2018-18363: Naomi Tesla References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 04-JAN-19 06.21.54.000000000 AM Modified: 09-JAN-19 06.00.22.000000000 AM Classification: Norton |
|||||||||
SYMSA1475 |
Norton Password Manager Address Spoof |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. Updates for Norton Password Manager, versions 6.2.0.1078 (Android) and 6.2.309 (iOS), have been released to address this issue. Note that the latest Norton Password Manager release are available to customers through the Google Play Store and the Apple App Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 07-FEB-19 10.59.22.000000000 AM Modified: 14-FEB-19 06.00.36.000000000 AM Classification: Norton |
|||||||||
SYMSA1476 |
Norton Core Arbitrary Code Execution |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Core product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton Core update, v278, has been released which addresses the aforementioned issue. Note that Norton Core updates are received to devices automatically via firmware updates to the router. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements -CVE-2019-9695: Moshe Wagner <moshe.wagner@gmail.com>References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 19-MAR-19 11.23.38.000000000 AM Modified: 10-APR-19 07.23.45.000000000 AM Classification: Norton |
|||||||||
SYMSA1479 |
Norton SEP Multiple Issues |
|||||||||||||||||
Advisory Status |
CLOSED |
|||||||||||||||||
| Summary |
Symantec has released updates to address issues that were discovered in the Norton Security, Symantec Endpoint Protection (SEP), Symantec Endpoint Protection Manager (SEPM), Symantec Endpoint Protection Small Business Edition (SEP SBE) and Symantec Endpoint Protection Cloud (SEP Cloud) products. --> |
|||||||||||||||||
| Affected Products |
|
|||||||||||||||||
| Issues |
Mitigation The aforementioned issues were validated by product team engineers. A set of product security updates to mitigate the listed issues are as follows:
Note that the latest releases of the mentioned products are available to customers through normal support channels. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 15-APR-19 11.07.45.000000000 AM Modified: 23-SEP-19 06.09.07.000000000 AM Classification: Norton |
|||||||||||||||||
SYMSA1483 |
Norton Password Manager Address Spoof |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. An update for Norton Password Manager for Android, version 6.3.0.2082, has been released to address this issue. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 06-JUN-19 06.05.35.000000000 AM Modified: 16-JUL-19 06.00.23.000000000 AM Classification: Norton |
|||||||||
SYMSA1493 |
Norton Password Manager Information Disclosure |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. An update for Norton Password Manager for Android, version 6.5.0.2104, has been released to address this issue. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 09-SEP-19 10.53.14.000000000 AM Modified: 16-SEP-19 06.00.17.000000000 AM Classification: Norton |
|||||||||
SYMSA1496 |
Norton App Lock Security Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
An update has been released to address an issue that was discovered in the Norton AppLock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.4.0.503, has been released which addresses the aforementioned issue. Note that the latest Norton App Lock release and patches are available to customers through the Google Play Store. At this time, there is no evidence of any exploitations or adverse customer impact from this issue. Consider the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Tom Tsongas Created: 13-NOV-19 06.58.06.000000000 AM Modified: 18-NOV-19 05.42.57.000000000 AM Classification: Norton |
|||||||||
SYMSA1499 |
Norton Password Manager Multiple Issues |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Norton LifeLock has released an update to address issues that were discovered in the Norton Password Manager product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation An update for Norton Password Manager for Android, version 6.6.2.5, has been released to address these issues. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. At this time, there is no evidence of any exploitations or adverse customer impact from these issues. Acknowledgements
References Additional DataLegacy ID: Owner: Tom Tsongas Created: 03-DEC-19 11.12.41.000000000 AM Modified: 05-DEC-19 05.42.32.000000000 AM Classification: Norton |
|||||||||
SYMSA1474 |
Symantec Ghost Solution Suite DLL Hijack |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Ghost Solution Suite (GSS) product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Symantec Ghost Solution Suite (GSS) update, version 3.3 RU1, has been released which addresses the aforementioned issue. Note that the latest Symantec Ghost Solution Suite (GSS) releases and updates are available to customers through normal support channels. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 22-JAN-19 11.02.02.000000000 AM Modified: 17-JUL-19 06.00.15.000000000 AM Classification: Norton |
|||||||||
SYMSA1473 |
Norton App Lock Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton App Lock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.4.0.445, has been released which addresses the aforementioned issue. Note that the latest Symantec Norton App Lock release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements CVE-2018-18363: Jeffrey Mustard (@MustardJeffrey) References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 04-JAN-19 06.21.54.000000000 AM Modified: 09-JAN-19 06.00.22.000000000 AM Classification: Veritas |
|||||||||
SYMSA1496 |
Norton App Lock Security Bypass |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
An update has been released to address an issue that was discovered in the Norton AppLock product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton App Lock update, version 1.4.0.503, has been released which addresses the aforementioned issue. Note that the latest Norton App Lock release and patches are available to customers through the Google Play Store. At this time, there is no evidence of any exploitations or adverse customer impact from this issue. Consider the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Tom Tsongas Created: 13-NOV-19 06.58.06.000000000 AM Modified: 18-NOV-19 05.42.57.000000000 AM Classification: Veritas |
|||||||||
SYMSA1476 |
Norton Core Arbitrary Code Execution |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Core product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton Core update, v278, has been released which addresses the aforementioned issue. Note that Norton Core updates are received to devices automatically via firmware updates to the router. At this time, Symantec is not aware of any exploitations or adverse customer impact from these issues. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements -CVE-2019-9695: Moshe Wagner <moshe.wagner@gmail.com>References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 19-MAR-19 11.23.38.000000000 AM Modified: 10-APR-19 07.23.45.000000000 AM Classification: Veritas |
|||||||||
SYMSA1475 |
Norton Password Manager Address Spoof |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. Updates for Norton Password Manager, versions 6.2.0.1078 (Android) and 6.2.309 (iOS), have been released to address this issue. Note that the latest Norton Password Manager release are available to customers through the Google Play Store and the Apple App Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 07-FEB-19 10.59.22.000000000 AM Modified: 14-FEB-19 06.00.36.000000000 AM Classification: Veritas |
|||||||||
SYMSA1499 |
Norton Password Manager Multiple Issues |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Norton LifeLock has released an update to address issues that were discovered in the Norton Password Manager product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation An update for Norton Password Manager for Android, version 6.6.2.5, has been released to address these issues. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. At this time, there is no evidence of any exploitations or adverse customer impact from these issues. Acknowledgements
References Additional DataLegacy ID: Owner: Tom Tsongas Created: 03-DEC-19 11.12.41.000000000 AM Modified: 05-DEC-19 05.42.32.000000000 AM Classification: Veritas |
|||||||||
SYMSA1470 |
Norton Password Manager XSS |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android (formerly Norton Identity Safe) product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation The issue was validated by the product team engineers. A Norton Password Manager for Android (formerly Norton Identity Safe) update, version 6.1.0.1045, has been released which addresses the aforementioned issue. Note that the latest Norton Password Manager for Android release and patches are available to customers through the Google Play Store. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 30-NOV-18 06.40.33.000000000 AM Modified: 06-DEC-18 06.00.27.000000000 AM Classification: Veritas |
|||||||||
SYMSA1483 |
Norton Password Manager Address Spoof |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. An update for Norton Password Manager for Android, version 6.3.0.2082, has been released to address this issue. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 06-JUN-19 06.05.35.000000000 AM Modified: 16-JUL-19 06.00.23.000000000 AM Classification: Veritas |
|||||||||
SYMSA1493 |
Norton Password Manager Information Disclosure |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Norton Password Manager for Android product. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue has been validated by Symantec. An update for Norton Password Manager for Android, version 6.5.0.2104, has been released to address this issue. Note that the latest Norton Password Manager release is available to customers through the Google Play Store. Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 09-SEP-19 10.53.14.000000000 AM Modified: 16-SEP-19 06.00.17.000000000 AM Classification: Veritas |
|||||||||
SYMSA1481 |
Symantec AV Engine Arbitrary File Deletion |
|||||||||
Advisory Status |
CLOSED |
|||||||||
| Summary |
Symantec has released an update to address an issue that was discovered in the Symantec AV Engine. --> |
|||||||||
| Affected Products |
|
|||||||||
| Issues |
Mitigation This issue was validated by the product team engineers. A Symantec AV Engine fix, version 13.0.9r17, has been released that addresses the aforementioned issue. Note that this update is specific to Mac endpoints only. AV Engine updates occur automatically via LiveUpdateTM; user interaction is not directly required. Rollout of this particular update occurred on 4/24/2019. At this time, Symantec is not aware of any exploitations or adverse customer impact from this issue. Symantec recommends the following measures to reduce risk of attack:
Acknowledgements
References Additional DataLegacy ID: Owner: Thomas Tsongas Created: 01-MAY-19 06.50.17.000000000 AM Modified: 08-MAY-19 11.55.39.000000000 AM Classification: Veritas |
|||||||||
SYMSA1503 |
Norton Power Eraser Privilege Escalation |
||||||||
Advisory Status |
CLOSED |
||||||||
| Summary |
Norton LifeLock has released an update to address an issue that was discovered in the Norton Power Eraser product. --> |
||||||||
| Affected Products |
Affected:
|
||||||||
| Issues |
Mitigation A Norton Power Eraser update, version 5.3.0.67, has been made available to address this issue. The latest Norton Power Eraser downloads are available to customers via the Norton Support portal. At this time, there is no evidence of any attempts at this exploit in the wild. Acknowledgements
References Additional DataLegacy ID: Owner: Created: Modified: Classification: |
||||||||