Jump to content
TCH-Thomas

Symantec Products Navcomui Activex Control Code Execution

Recommended Posts

From: Secunia http://secunia.com/advisories/25215/

Rating: Highly critical

 

Description:

Secunia Research has discovered two vulnerabilities in various Symantec products, which can be exploited by malicious people to compromise a user's system.

 

The vulnerabilities are caused due to errors in the AxSysListView32 and AxSysListView32OAA ActiveX controls (NavComUI.dll) when handling the "AnomalyList" and "Anomaly" properties respectively as they take a VARIANT* as argument.

 

Successful exploitation allows execution of arbitrary code.

 

The vulnerabilities have been confirmed in Norton Internet Security 2006 including Norton AntiVirus 12.7.0.2. According to the vendor, the following versions are affected:

* Norton AntiVirus 2006

* Norton Internet Security 2006

* Norton Internet Security, Anti Spyware Edition 2005

* Norton System Works 2006

 

Solution:

The vendor has issued a fix, which is available via LiveUpdate in Interactive Mode.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...