Train

PDA

توجه ! این یک نسخه آرشیو شده میباشد و در این حالت شما عکسی را مشاهده نمیکنید برای مشاهده کامل متن و عکسها بر روی لینک مقابل کلیک کنید : Norton AntiVirus Help Interface Privilege Escalation


NI3
10-30-2003, 11:35 AM
Secunia Advisory: SA7394
Release Date: 2002-10-25
Last Update: 2003-10-27


Critical: Less critical
Impact: Privilege escalation

Where: Local system



Software: Norton AntiVirus Corporate Edition 7.x




Description:
A vulnerability has been reported in Norton AntiVirus Corporate Edition 7.5 and 7.6, which can be exploited by malicious, local users to escalate privileges.

The problem is that the Norton AntiVirus invokes the Windows Help interface with LocalSystem privileges. This can be exploited to execute arbitrary commands on a system with escalated privileges.


Solution:
Symantec / Norton has released new versions, which are not vulnerable.

7.5.1 Build 62 and later are not vulnerable.
7.6.1 Build 35a and later are not vulnerable.


Reported by / credits:
ERRor





Found: 2 Related Secunia Security Advisories


- Symantec/Norton Anti Virus Denial of Service Vulnerability
- Symantec Norton AntiVirus Fails to Detect Malware on Floppy

NI3
10-30-2003, 11:36 AM
Secunia Advisory: SA9427
Release Date: 2003-08-04


Critical: Moderately critical
Impact: DoS

Where: From local network



Software: Norton AntiVirus Corporate Edition 7.x
Symantec Anti Virus Corporate Edition 8.x




Description:
A vulnerability has been identified in Symantec/Norton Anti Virus, which can be exploited by a malicious person to cause a DoS (Denial of Service) on a vulnerable system.

The vulnerability is caused due to an error in the Quarantine Server (qserver.exe) when handling connections to the TCP listener port. This can be exploited to consume all CPU ressources by connecting to the service and then disconnecting abnormally prior to sending data.

The vulnerability has been reported in the following versions:
Norton AntiVirus Corporate Edition version 7.61
Symantec Anti Virus Corporate Edition version 8.01
Symantec Anti Virus Corporate Edition version 8.1


Solution:
Install an updated version of the Quarantine Server (see the original advisory for version info and installation instructions).


Reported by / credits:
Qualys Security Research Team


Original Advisory:
[Only registered and activated users can see links]